How we run an engagement

A defined process from scope to verified remediation — so you know what happens, when it happens, and exactly what you receive at the end.

The engagement

Four phases, no surprises.

Scoping and authorisation

We define targets, in-scope user roles, environments, and testing windows — and document what is explicitly out of scope. Written authorisation is agreed before any testing activity begins, along with an emergency contact and escalation path for critical findings.

Output: signed scope document and rules of engagement

Reconnaissance and manual testing

We map the application's attack surface, then work through it by hand across every authenticated role and trust boundary. Automated tooling supports discovery and coverage; exploitation and validation are always manual. Critical findings are reported to you immediately on confirmation rather than held until the report.

Output: interim notification of critical and high-severity findings

Analysis and reporting

Every confirmed finding is documented with reproduction steps, evidence, a CVSS v3.1 vector, standards mapping, and remediation guidance written for the engineers who will implement it. The report opens with an executive summary suitable for non-technical stakeholders.

Output: full engagement report

Remediation support and retest

We remain available to clarify findings while your team implements fixes. Once remediation is deployed, we re-test each finding and issue an updated report recording each as fixed, partially fixed, or outstanding — evidence you can hand to a customer or auditor.

Output: retest report with verified remediation status

Deliverables

What is actually in the report.

The report is the product. It is written to be read by two audiences at once — leadership who need the risk picture, and engineers who need to reproduce and fix the issue.

Executive summary

The engagement scope, the overall risk picture, and what the findings mean commercially — written without jargon for stakeholders who will not read the technical detail.

Findings summary

Every finding at a glance with severity distribution and category breakdown, so priorities are obvious before anyone opens the detail sections.

Per-finding detail

Affected components, step-by-step reproduction, supporting evidence, confidentiality/integrity/availability impact, and likelihood assessment.

Severity and mapping

CVSS v3.1 base vector and score, OWASP Top 10 category, and STRIDE classification for each finding — defensible severity, not an opinion.

Remediation guidance

Specific corrective actions per finding, written to be implementable rather than generic best-practice restatement.

Retest record

Following remediation, each finding is formally re-tested and marked fixed, partially fixed, or not fixed — with the evidence behind that determination.

Standards

Frameworks we test and report against.

Testing frameworks

  • OWASP Web Security Testing Guide (WSTG)
  • OWASP Application Security Verification Standard (ASVS)
  • OWASP API Security Top 10
  • OWASP Top 10 for LLM Applications
  • CIS Benchmarks for cloud configuration

Classification and scoring

  • CVSS v3.1 base scoring with published vectors
  • OWASP Top 10 category mapping
  • STRIDE threat classification
  • Impact assessment across confidentiality, integrity, and availability

Rules of engagement

How we protect your environment while testing it.

Written authorisation first

No testing begins without a signed scope defining exactly what is authorised. We test only what is in scope.

Non-destructive by default

We do not run denial-of-service testing, destructive payloads, or data-modifying attacks unless explicitly authorised in writing.

Agreed testing windows

Testing runs inside windows you approve, with an escalation contact available throughout in case of any operational impact.

Immediate critical escalation

Critical findings — particularly those indicating active exposure — are reported to you on confirmation, not deferred to the report.

Confidentiality

How we handle your data and your name.

Engagement data

Findings, evidence, and any client data encountered during testing are held only as long as the engagement and its retest require, then securely destroyed on request. We will sign your NDA and data-processing terms before scoping.

Your identity

We do not name clients, products, or engagements publicly without written permission. Any engagement referenced on this site is anonymised, and stays that way unless the client explicitly agrees otherwise.

Ready to scope an engagement?

Tell us about your application and timeline. We will come back with scoping questions and a proposed approach.