Methodology

How an Engagement Runs, Start to Finish

Every engagement follows the same disciplined process, whatever the target. Here's exactly what happens at each stage.

1. Scoping & NDA

We define the systems in scope, the testing window, and rules of engagement in writing, and sign a mutual NDA before any technical work starts. You'll get a fixed quote at this stage, not an open-ended estimate.

2. Reconnaissance

Passive and active information gathering on the target — technology stack, exposed services, subdomains, and publicly available information relevant to the assessment.

3. Vulnerability Identification

Automated tooling (Burp Suite, Nmap, Nuclei, and purpose-built scripts) provides broad coverage quickly, flagging candidate issues for manual follow-up.

4. Manual Exploitation

A human tester manually verifies and exploits each meaningful candidate finding to confirm real-world impact, and actively looks for the business-logic and chained-attack issues no scanner can find.

5. Risk Rating

Every confirmed finding is scored with CVSS and rated by real-world exploitability and business impact — not just theoretical severity.

6. Reporting

You receive an executive summary for stakeholders and a technical report per finding: description, proof of concept, affected assets, risk rating, and specific remediation guidance.

7. Debrief Call

A walkthrough call with your engineering team to answer questions and make sure the report translates cleanly into a remediation plan.

8. Retest

Once you've applied fixes, we retest every finding and issue a retest report confirming closure — included in the original engagement price.

Standards

Frameworks Our Testing Is Grounded In

OWASP

  • OWASP Testing Guide
  • OWASP ASVS
  • OWASP API Security Top 10
  • OWASP MASVS

Industry Methodologies

  • PTES (Penetration Testing Execution Standard)
  • OSSTMM
  • NIST SP 800-115

Threat Modeling

  • MITRE ATT&CK framework
  • CIS Benchmarks (cloud & network)
Rules of Engagement

How We Keep Testing Safe

Written Authorization

No testing begins without a signed scope document naming exactly what's authorized.

Agreed Testing Window

Higher-risk tests are scheduled for low-traffic periods, agreed with you in advance.

No Destructive Techniques

Denial-of-service and data-destructive techniques are excluded unless explicitly authorized. See our Responsible Disclosure policy.