Our approach
Why we exist, and how we work
Independent testing for teams that built the difficult part and need somebody to challenge it before strangers do.
Why
Shipping it is the hard part. Nobody checks it.
Many applications reach the internet without a security engineer ever challenging their assumptions. A test does not make an application safe, but it lets you learn from a report with a fix beside it instead of from a customer on a Sunday.
How we work
Five things we hold to
-
Authorised testing only
Scoped and authorised in writing before anything starts.
-
Findings you can reproduce
Each one carries the request that triggers it and the steps to reach it.
-
Ranked by real risk
Ordered by what it would cost you, not by a number a calculator produced.
-
Closed, not just reported
Your engineers fix the findings, and we retest them under the published terms.
-
Direct contact
You talk to the people doing the testing. There is no account manager.
Need your application tested?
Send a paragraph about what you built. That is enough to start.