The buying process

How an engagement starts

No online checkout. No automated pentest. No customer portal to configure. Just a straightforward process from enquiry to results.

01

Request

You submit a short form describing your organization and objectives. This does not authorize any testing.

02

Scope

A short conversation to understand your environment, concerns, and objectives, and agree an appropriate scope — what's included, what's excluded, and how deep to go.

03

Proposal

You receive a straightforward, itemized proposal: objective, scope, exclusions, methodology, deliverables, timing, price and assumptions. No surprises.

04

Authorize

We agree written scope, authorization and Rules of Engagement — covering the authorized organization, target scope, exclusions, testing window, allowed and prohibited techniques, emergency contact, data handling and confidentiality. Testing never starts before this is signed.

05

Assess

Discovery, analysis, human validation, and — where authorized — attack-path investigation, carried out against the agreed scope and timeline.

06

Report

You receive the full report: executive summary, asset overview, validated findings with evidence, attack paths if identified, prioritized remediation, and assessment limitations.

07

Review

A live debrief call with the person who did the work — to walk through findings, answer questions, and discuss remediation priorities.

Start with a no-obligation request

We review your environment and objectives, agree an appropriate scope, and provide a straightforward proposal.

Get started

What does your organization look like from the outside?

Request an External Attack Surface Check and find out what an attacker can see before they do.