Frequently Asked

Before you reach out.

Everything you need to know about scope, reports, re-tests, training, and how we operate — answered by the people who actually run the engagements.

Do you test without written authorization?+

No. We only operate under a signed scope of work and rules of engagement. This protects you, your users, and our team.

How long does a typical engagement take?+

Most assessments run 1–3 weeks depending on scope, with critical findings flagged to your team as soon as they're confirmed — not held until the final report.

Do you offer a re-test after remediation?+

Yes. One re-test on critical and high-severity findings is included in every assessment engagement.

Can training be delivered in-house?+

Yes. Our training track runs as public cohorts or as a private, in-house program scoped to your team's stack and threat model.

What does a report actually include?+

An executive summary, a ranked findings list with evidence and business impact, and step-by-step remediation guidance for each issue.

What certifications do your testers hold?+

Every lead tester holds OSCP (Offensive Security Certified Professional) and our trainers maintain active CEH (Certified Ethical Hacker) credentials, refreshed annually.

How do you handle critical findings during an engagement?+

Critical findings are flagged to your designated point of contact within hours of confirmation — we don't wait for the final report to alert you to something that needs immediate attention.

Do you work with remote teams or only on-site?+

We're remote-first and work with teams globally. All testing is conducted remotely unless a client specifically requests an on-site engagement.

Still have a question?

We're happy to walk you through scope, methodology, or pricing — no pressure, just answers.

Ask us anything

“The clarity around scope and deliverables made the whole process feel collaborative, not adversarial.”

— Director of Security, Fintech Company