Scope
What we are not
SkullSploit tests web applications and APIs. We do not widen that engagement quietly when another kind of work is needed.
Skull Solutions
The defensive half has a different owner
The work before and after a test belongs to Skull Solutions, not SkullSploit. That separation keeps the tester from marking its own remediation work.
-
Application security consulting
Security architecture review, threat modelling, secure code review and attack surface review: how the application was designed, and what it was meant to defend against.
-
Secure software engineering
Closing findings in your codebase, and building the parts where getting the security wrong is the whole risk. Not general development, and never a product build with a security label on it.
Ask us either way. If the work belongs with Skull Solutions, we will say so and hand you over.
Elsewhere
Work we refer outside the company
-
Other offensive work
Network, wireless and physical testing, red teaming, social engineering, specialist offensive research, and exploit development.
-
Live incidents
Incident response while an incident is in progress.
-
Accredited audits
Work that must be signed by an accredited assessor or produce a compliance certificate.
Not sure where it belongs?
Send the question once. We will tell you who should own it.