These are the questions we hear most often from security leads, engineering managers, and procurement teams. The answers below are the same ones we give on a call. If yours is not covered, write to us and a practitioner will reply within one business day.
Write to [email protected] or use the form on our contact page. We reply within one business day, execute a mutual NDA, and then hold a short scoping call to understand your targets, objectives, and constraints. Within a few days of that call you receive a fixed proposal covering methodology, team composition, timeline, and price. Once you approve it, we agree on dates and lock the team.
Yes, always. Scoping requires architecture detail, URLs, and sometimes documentation you would not share with an outside party otherwise, so a mutual NDA comes before any of it changes hands. We have a standard template ready, and we are equally comfortable signing yours if it covers mutual obligations.
Scope is defined by what needs testing and to what depth: the number of applications and user roles, API operations, hosts and network segments, cloud accounts, and the objectives you care about. Price follows from the effort a proper assessment of that scope requires, quoted as a fixed fee for the engagement. There is no hourly meter and no surprise overrun.
If testing reveals that the environment is materially larger than described, we tell you and agree on next steps before expanding anything. We would rather resize a scope openly than deliver shallow coverage quietly.
The difference is how much knowledge and access we start with. Black box begins from an outside position with no credentials, which models an opportunistic external attacker but spends a share of the schedule on discovery. Gray box adds test accounts and documentation, so more of each day goes into depth rather than reconnaissance; it is the model we recommend for most application and API work. White box adds source code or configuration access and delivers the highest assurance per hour of testing, since we can trace a suspicious behavior straight to its cause. The right choice depends on the question you want answered, and we help you pick during scoping.
A single web application, API, or external network assessment typically runs one to three weeks of active testing, depending on size and depth. Internal network work, cloud reviews, and multi-asset scopes run longer, and red team operations are measured in weeks rather than days by design. Your proposal states the exact schedule, and the report follows within five business days of the last test day.
Either, and we decide together during scoping. Production gives the truest picture of what an attacker faces, and we test it carefully: no destructive payloads, agreed testing windows, rate limits respected, and an emergency contact on both sides. Staging is the right place for intrusive test cases and load-sensitive components, provided it mirrors production configuration closely. Many clients split the difference, running intrusive cases against staging and verifying a subset of findings in production.
An executive summary written in plain language for leadership, followed by technical findings. Each finding includes a description, the affected assets, step-by-step reproduction instructions, supporting evidence such as request and response data or screenshots, a CVSS v3.1 rating, and remediation guidance aimed at the team that will implement the fix. The report closes with a methodology and coverage appendix, so you know exactly what was tested and what was not. Every report is followed by a live debrief call with the testers.
Yes. Every finding carries a CVSS v3.1 vector and score. We also add a short written justification for each rating, because a vector string on its own can mislead: a technically severe issue behind three layers of authentication is a different problem from the same issue on an unauthenticated endpoint. The score gives you a common language for tracking; the justification gives you the context to prioritize honestly.
It is. Every assessment includes one retest of fixed findings at no additional cost. When your team has remediated, we verify each fix against the original reproduction path, check that the change did not introduce an obvious regression nearby, and issue an updated report marking each finding as resolved or still open. Retests are typically scheduled within an agreed window after report delivery.
Yes, within the bounds of an assessment. Remediation guidance in the report is written for implementers, not auditors, and the debrief call is a working session where your engineers can ask the testers anything. During the remediation window the engagement team remains reachable for follow-up questions about specific findings. If you want deeper involvement, such as reviewing a proposed redesign, we can scope advisory time separately.
Only the recipients you designate. Reports are delivered over an encrypted channel agreed at kickoff, typically PGP-encrypted mail or a secure transfer link, never as a plain email attachment. Inside our firm, access is restricted to the engagement team, and engagement material is retained and destroyed on the schedule set in your agreement. Our Trust & Data Handling page describes the full lifecycle.
A feed sends you indicators; we send you judgments. Monitoring is configured around your organization specifically: your domains, brands, executives, infrastructure, and suppliers. Human analysts triage everything before it reaches you, so every alert has been verified as relevant, ranked by severity, and paired with recommended actions. You also get a named analyst who knows your environment, not a ticket queue.
A modest starter set: your domains, brand and product names, the public roles of executives you want covered, external IP ranges, and the third parties whose compromise would hurt you. We hold an onboarding call to tune priorities, deliver a baseline report of your current exposure, and then move into continuous monitoring. Most organizations are fully onboarded within days, not weeks.
Credential exposures that appear valid for your systems, including those recovered from infostealer logs, are escalated as soon as an analyst validates them, with 24/7 handling for critical alerts. The alert tells you which account, which source, and what to do first. Lower-severity material, such as stale or already-rotated credentials, is grouped into your periodic summary rather than paged out at night.
Yes, takedown support is part of the service. We collect evidence, file with the registrar, hosting provider, and relevant blocklist operators, and track the case through to removal. Because takedown timelines depend partly on how responsive those parties are, we also give you immediate mitigations while the process runs: indicators to block, mail rules to apply, and wording to warn staff or customers if the campaign is active.
The addresses are allocated to your organization and to no one else. No other customer's traffic ever egresses from them, so their reputation is entirely under your control and you can allowlist them with confidence in SaaS admin panels, firewalls, and partner systems. The gateways behind them are single-tenant as well: your organization runs on its own instances, not on shared infrastructure with per-customer routing.
We do not inspect or store the content of your traffic. We do keep the connection metadata needed to operate the service: authentication events, session timestamps, assigned tunnel addresses, and aggregate bandwidth. That is what lets us troubleshoot connectivity, detect abuse of a compromised key, and bill accurately. Exactly what is collected, how long it is retained, and who can access it is scoped and disclosed in your service agreement before you sign, so there is nothing to discover later.
Yes. Gateways deploy in our managed cloud regions, inside your own cloud accounts, or on hardware in your facilities. An on-premises deployment keeps the data path entirely within infrastructure you control while retaining the same WireGuard and OpenVPN protocols, per-user key model, and private DNS. Mixed topologies are common, for example cloud gateways for the remote workforce and an on-premises gateway in front of internal systems.
Effectively immediate. Each user holds an individual key, and revoking one propagates to your gateways within seconds. A revoked key cannot establish a new session, and its active sessions are terminated. When an employee leaves or a laptop goes missing, access ends the moment your administrator acts, without touching anyone else's configuration.
Senior practitioners who work for us. We never outsource or subcontract delivery, and there is no junior bench learning on your systems. The people on your scoping call are the people who execute the engagement, and you communicate with them directly throughout. That is a structural choice: small teams of experienced testers produce better findings than large teams of interchangeable ones.
On the principle of least data for the shortest time. We collect only what the engagement requires, store evidence encrypted at rest, restrict access to the assigned team, and destroy engagement material on the schedule defined in your agreement. Findings are never reused, anonymized into marketing, or shared across clients. The full policy is documented on our Trust & Data Handling page.
We do. Beyond one-time assessments, we run standing programs: recurring assessments aligned to your release cycle, quarterly external testing, or a retainer that lets your team pull us in when a significant change ships. Continuity has a compounding benefit, because the same testers return each cycle carrying real knowledge of your architecture, your history, and where regressions tend to appear.
Send the specifics of your situation and a senior practitioner will answer within one business day. An NDA is ready before any sensitive detail changes hands.