Skip to content

Four practices, one point of responsibility

Instead of three vendors passing the problem to each other.

One perimeter, four practices

Every line on the diagram is a separate vendor with the usual approach. With us it is one point of responsibility.

  • Pentest and audit
  • Compliance and consulting
  • Bug sweeps (TSCM)
  • Device protection

Methodologies we work by

No "proprietary methods", only open standards your auditor and your developer know.

  • OWASP WSTG
  • OWASP API Top 10
  • OWASP MASVS
  • PTES
  • NIST SP 800-115
  • ISO 27001
  • SOC 2
  • NIS2
  • DORA
  • GDPR

How the work goes

  1. 01

    Conversation

    We find out what exactly we protect and from whom. No forty-question questionnaires.

  2. 02

    Scope and contract

    We fix the boundaries, timeline and report format. We sign an NDA.

  3. 03

    The work

    We test and document every finding with evidence and a risk level.

  4. 04

    Report and fixes

    We explain what to fix first. We retest after the fixes.

Who we are for

Six typical situations people come to us with. If you recognise yours, the next step is a short conversation.

Scanner or pentest

A scanner is useful, but it is not a security assessment. Here is the difference.

Vulnerability scannerPentest
What it findsKnown vulnerabilities from a databaseReal attack scenarios, including logic
False positivesHundreds, for you to triageEvery finding verified by hand
Attack chainsDoes not see themChains small findings into a critical one
ReportA technical listFor the director, the developer and the auditor
RetestThe same scan againConfirmation that it is fixed

How we work

How this site is protected

We do not ask you to take our word for it. Check for yourself.

No database
The site is static. There is nothing to break into: no admin panel, no sessions, no passwords.
Requests are not stored
The form sends your message straight to our Telegram and keeps no copy on the server.
Security headers
CSP, HSTS, no embedding in other sites. Check it on securityheaders.com.
No trackers
No cookies, no pixels, no third-party analytics.

Guide

Short articles about what we do and why. Five minutes of reading that saves an hour of conversation.

All articles

Common questions

How much does a pentest cost?

It depends on the scope: the number of applications, the size of the network, the access mode. A small web app and a large infrastructure differ many times over. After a short conversation we give a fixed price and timeline; we do not publish prices on the site because without scope they mislead.

Will you break something during the pentest?

We work within agreed boundaries and rules: no DoS, no data destruction, destructive actions only in a test environment and after separate permission. We warn about risky steps in advance.

How long does the work take?

A pentest of one application: one to two weeks including the report. Infrastructure: two to four weeks. A bug sweep: from a few hours to a day. ISO 27001 preparation: three to nine months depending on the starting point.

Do you sign an NDA?

Yes, before any work begins. We can sign your template or provide ours.

Can I contact you anonymously?

Yes. The form has a confidential mode: no name or phone, only a Signal or Session handle. For a bug sweep we arrange a meeting without witnesses.

Write to us

The message goes straight to our Telegram. Nothing stays on the server.

Telegram

What you need

By sending the form you agree that we contact you through the channel you provided.