How we test, rate and report
A public methodology is how you tell a real practice from a scan with a letterhead. This is the process we run unless your rules of engagement say otherwise.
Authorisation and scope
Written permission, named targets, accounts, windows, emergency contacts, and a no-strike list. Fixed quote in AUD before testing starts.
Reconnaissance
We map the in-scope surface: hosts, apps, roles, APIs, cloud principals. Out of scope stays out of scope. Discovery is not an excuse to wander.
Manual testing
Authenticated, attacker-style testing. Scanners for breadth. Humans for logic, access control and chains. Daily check-ins. Same-day call on criticals.
Severity
CVSS 3.1 plus a contextual rating. If a 'medium' exposes customer data in your environment, the report will say so in English.

Written to be acted on
Executive summary for leadership. Per-finding detail for engineers: description, evidence, reproduction, affected assets, a concrete fix. Debrief call included. Retest included.
- No unverified scanner rows.
- No denial-of-service unless you schedule it.
- No social engineering unless it is an agreed line in the SoW.
Standards we map to
- OWASP Top 10, ASVS, MASVS and API Security Top 10
- PTES for engagement structure
- NIST SP 800-115 for technical assessment practice
- CIS Benchmarks for cloud configuration reviews
- CVSS 3.1 for numeric severity
What we do not do
- We do not sell certifications we do not hold.
- We do not dump mass data to "prove" a finding. A bounded proof is the standard.
- We do not test third parties you do not have written authority to test.
Process questions
Do you follow PTES or OWASP?
Both. PTES for engagement structure. OWASP Top 10, ASVS, MASVS and the API Security Top 10 for application work. NIST SP 800-115 for technical assessment practice. CVSS 3.1 for scores.
Will you put unverified scanner output in the report?
No. Tools are for coverage. Every finding we ship has been reproduced by a person.
Can you work to our rules of engagement?
Yes. Yours or ours. Nothing starts until both sides have signed authorisation.
See it applied to your stack
The methodology flexes to web, API, mobile, cloud and network. Pick a service or go straight to a quote.