// Methodology

How we test, rate and report

A public methodology is how you tell a real practice from a scan with a letterhead. This is the process we run unless your rules of engagement say otherwise.

Working through a test scope at a desk

Authorisation and scope

Written permission, named targets, accounts, windows, emergency contacts, and a no-strike list. Fixed quote in AUD before testing starts.

Reconnaissance

We map the in-scope surface: hosts, apps, roles, APIs, cloud principals. Out of scope stays out of scope. Discovery is not an excuse to wander.

Manual testing

Authenticated, attacker-style testing. Scanners for breadth. Humans for logic, access control and chains. Daily check-ins. Same-day call on criticals.

Severity

CVSS 3.1 plus a contextual rating. If a 'medium' exposes customer data in your environment, the report will say so in English.

Working through findings at a desk
// Reporting

Written to be acted on

Executive summary for leadership. Per-finding detail for engineers: description, evidence, reproduction, affected assets, a concrete fix. Debrief call included. Retest included.

  • No unverified scanner rows.
  • No denial-of-service unless you schedule it.
  • No social engineering unless it is an agreed line in the SoW.

Standards we map to

  • OWASP Top 10, ASVS, MASVS and API Security Top 10
  • PTES for engagement structure
  • NIST SP 800-115 for technical assessment practice
  • CIS Benchmarks for cloud configuration reviews
  • CVSS 3.1 for numeric severity

What we do not do

  • We do not sell certifications we do not hold.
  • We do not dump mass data to "prove" a finding. A bounded proof is the standard.
  • We do not test third parties you do not have written authority to test.
// FAQ

Process questions

Do you follow PTES or OWASP?

Both. PTES for engagement structure. OWASP Top 10, ASVS, MASVS and the API Security Top 10 for application work. NIST SP 800-115 for technical assessment practice. CVSS 3.1 for scores.

Will you put unverified scanner output in the report?

No. Tools are for coverage. Every finding we ship has been reproduced by a person.

Can you work to our rules of engagement?

Yes. Yours or ours. Nothing starts until both sides have signed authorisation.

See it applied to your stack

The methodology flexes to web, API, mobile, cloud and network. Pick a service or go straight to a quote.

Get a fixed quote