We reply with scoping questions
Application type, user roles, environment availability, and your timeline — enough to size the engagement accurately.
Tell us what you have built, why you are testing, and when you need it done. We respond within two business days with scoping questions and a proposed approach.
Get in touch
We work remotely with clients across time zones. Email is the fastest way to reach us, and everything discussed is treated as confidential from the first message.
Application type, user roles, environment availability, and your timeline — enough to size the engagement accurately.
Recommended service, duration, deliverables, and commercials. We will sign your NDA at or before this stage.
Written scope and rules of engagement agreed, testing window booked, and your escalation contact confirmed.
FAQ
A typical mid-sized web application takes around two weeks of active testing, followed by a remediation window and a retest. Smaller, tightly scoped targets take less. We confirm the exact duration during scoping rather than quoting blind — the number of user roles and the amount of custom business logic matter more than raw page count.
Access to a suitable environment, test credentials for each user role you want assessed, and a written authorisation confirming scope. If you have API documentation or architecture notes, they help us find more in less time — but they are not mandatory.
We prefer a staging environment that mirrors production. Where testing must run against production, we agree testing windows in advance, exclude destructive techniques, and keep an escalation contact available throughout. That decision is always yours and is documented in the rules of engagement.
Yes — routinely, and before detailed scoping. We will also work under your data-processing terms and any client-specific security requirements. We do not name clients publicly without written permission.
A verification retest is included in every engagement. Once your team has deployed fixes, we re-test each finding and issue an updated report recording verified remediation status — which is usually the document your customer or auditor actually wants to see.
Yes. The report is yours. It is deliberately structured with an executive summary that can be shared with non-technical stakeholders, and many clients use the retest report as evidence in customer security reviews and procurement questionnaires.
Automated scanners match known signatures and misconfigurations. They do not understand that a particular user role should not be able to modify another tenant's records, or that a specific sequence of legitimate requests produces an illegitimate outcome. Those business-logic and access-control flaws are where real breaches happen, and finding them requires a human. We use tooling for coverage, then test by hand.
Yes. We operate remote-first and have delivered engagements for international clients, working across time zones for scoping calls, critical-finding escalation, and report walkthroughs.