Scoping call
Free. 30 to 90 minutes depending on engagement complexity. We learn the surface, the question, and the deadline. You leave the call knowing whether we are the right firm.
The person on the scoping call is the person testing. The person testing is the person writing the report. The person writing the report is the person you talk to on the readout call. No team rotation, no junior pivot, no handoff loss.
The five steps.
Free. 30 to 90 minutes depending on engagement complexity. We learn the surface, the question, and the deadline. You leave the call knowing whether we are the right firm.
Scope, methodology references, deliverables, timeline, price. All in writing before any work starts. Signed by both sides.
Two to eight weeks of active testing depending on scope. Daily updates on critical findings. Slack channel or email, your choice.
Findings written up with severity, exploit chain, fix steps, retest checklist. Live 60 to 90 minute walkthrough with your engineering team.
One round within 30 days of the report. Each finding re-verified, marked resolved or open with notes. Attestation letter delivered.
What stays the same across engagement types.
Why this model.
The engineer who finds a bug knows exactly how it works and what fix will hold. Handoff loses that context.
Fixed fee aligns us with the outcome. Hourly aligns the consultancy with billable hours.
Daily updates mean your team can fix critical findings before the engagement ends. Report becomes the wrap-up, not the first revelation.
Single named engineer + attestation letter is the format SOC 2 / ISO 27001 auditors expect to see.
What we do not do.
Hourly billing rewards slow testing. Most enterprise security buyers cannot get T&M past their CFO in 2026 anyway.
You meet your engineer on the scoping call. You work with them for the engagement. Same person. Always.
Scanner output is the starting point, not the deliverable. Every finding is manually verified.
Findings include line numbers, code paths, suggested fixes. Engineers can ship from the report.
Process FAQ.
A scoping call within 48 hours, an SOW within a week, kickoff within two to four weeks depending on engineer availability. Faster on request when capacity allows.
For larger engagements we run two or three engineers in parallel, each owning a scoped slice. You always have a single named lead.
Mid-engagement pauses are fine within reason. We hold the engineer for up to four weeks. Beyond that we re-schedule.
No. Every engagement is run by named senior engineers on staff. We do not white-label to other firms.
Yes. Most engagements have an open Slack channel with your team. Some clients enjoy shoulder-surfing; others want a quiet engagement. Either works.
Free, no NDA needed, 30 to 60 minutes. You leave knowing whether we fit and what the next step costs.