How an Engagement Runs, Start to Finish
Every engagement follows the same disciplined process, whatever the target. Here's exactly what happens at each stage.
1. Scoping & NDA
We define the systems in scope, the testing window, and rules of engagement in writing, and sign a mutual NDA before any technical work starts. You'll get a fixed quote at this stage, not an open-ended estimate.
2. Reconnaissance
Passive and active information gathering on the target — technology stack, exposed services, subdomains, and publicly available information relevant to the assessment.
3. Vulnerability Identification
Automated tooling (Burp Suite, Nmap, Nuclei, and purpose-built scripts) provides broad coverage quickly, flagging candidate issues for manual follow-up.
4. Manual Exploitation
A human tester manually verifies and exploits each meaningful candidate finding to confirm real-world impact, and actively looks for the business-logic and chained-attack issues no scanner can find.
5. Risk Rating
Every confirmed finding is scored with CVSS and rated by real-world exploitability and business impact — not just theoretical severity.
6. Reporting
You receive an executive summary for stakeholders and a technical report per finding: description, proof of concept, affected assets, risk rating, and specific remediation guidance.
7. Debrief Call
A walkthrough call with your engineering team to answer questions and make sure the report translates cleanly into a remediation plan.
8. Retest
Once you've applied fixes, we retest every finding and issue a retest report confirming closure — included in the original engagement price.
Frameworks Our Testing Is Grounded In
OWASP
- OWASP Testing Guide
- OWASP ASVS
- OWASP API Security Top 10
- OWASP MASVS
Industry Methodologies
- PTES (Penetration Testing Execution Standard)
- OSSTMM
- NIST SP 800-115
Threat Modeling
- MITRE ATT&CK framework
- CIS Benchmarks (cloud & network)
How We Keep Testing Safe
Written Authorization
No testing begins without a signed scope document naming exactly what's authorized.
Agreed Testing Window
Higher-risk tests are scheduled for low-traffic periods, agreed with you in advance.
No Destructive Techniques
Denial-of-service and data-destructive techniques are excluded unless explicitly authorized. See our Responsible Disclosure policy.