
Guide
Brief and to the point about what we do and why. So you understand what you are paying for before the first call.
Articles

What a pentest is and how it differs from a vulnerability scanner
A scanner finds known holes from a list. A pentester thinks like an attacker and chains small things into a real breach.
4 min read
Types of pentest: web, API, mobile apps, infrastructure, cloud, people
Each type checks its own layer. Together they give the picture, separately only a fragment.
5 min read
How to prepare for a pentest so you do not overpay
Five things done before the start that save days of work.
3 min read
What a pentest report must contain
If only the pentester understands the report, it does not work. A checklist for judging any report.
3 min read
How a bug sweep works
What we do in an office, a car or a flat, which instruments we use and why it takes hours.
5 min read
Signs that you may be listened to
None of them is proof, but two or three together are a reason to check.
3 min read
GrapheneOS: what it is and who really needs it
An operating system for Pixel without Google services by default. Not for everyone, but for some the only option.
4 min read
Secure communications: messengers, email, hardware keys
Three things that close most real risks for a person, not for a server.
4 min read
ISO 27001 or SOC 2: which to choose
Both are about managing security systematically. The difference is who you prove it to.
4 min read
NIS2 and DORA: who is affected and what to do
Two European frameworks that turn cybersecurity from a recommendation into an obligation with management liability.
4 min readTerms
Words you will hear from us and from auditors. Reports are hard to read without them.
- Pentest
- Penetration test: a controlled attack on a system with the owner's permission, to find ways in before others do.
- Vulnerability
- A weak spot in a system through which the confidentiality, integrity or availability of data can be violated.
- Exploit
- A method or code that uses a vulnerability to get a result: access, data, command execution.
- CVSS
- A 0 to 10 scale for rating the severity of a vulnerability. Above 9 means critical.
- OWASP
- A community that publishes methodologies and lists of the most common vulnerabilities in web and mobile apps (Top 10, WSTG, MASVS).
- Red team
- A simulation of a real targeted attack on a company without warning most employees, to test detection and response.
- Social engineering
- An attack on people rather than technology: phishing, calls from "support", a request to hold the door.
- Phishing
- A forged email, website or message that makes you enter a password or open a file.
- ISMS
- Information security management system: the policies, roles, risks and controls required by ISO 27001.
- Gap analysis
- A comparison of the current state with the requirements of a standard or regulator. The result: a list of gaps and a plan.
- vCISO
- Virtual chief information security officer: an external expert who performs the CISO role part-time, without a staff position.
- TSCM
- Technical surveillance countermeasures: the search for hidden microphones, cameras, trackers and transmitters.
- Planted device
- A hidden microphone, camera, GPS tracker or transmitter installed without the knowledge of the owner of the premises or car.
- Non-linear junction detector
- An instrument that finds semiconductor electronics even when switched off: bugs in walls, furniture, gifts.
- Spectrum analyser
- An instrument that shows all radio transmissions in a range and lets you tell legitimate ones (Wi-Fi, mobile) from foreign ones.
- GrapheneOS
- A hardened operating system for Google Pixel without built-in Google services, with strengthened app isolation.
- Hardware key
- A physical device (FIDO2, for example YubiKey) for logging into an account. Cannot be intercepted like an SMS code.
- End-to-end encryption
- Only the recipient decrypts the message; the intermediary server sees only encrypted data.
- Threat model
- The answer to the question: from whom, what and at what cost are you protecting. It defines which measures are needed and which are excessive.
- NDA
- Non-disclosure agreement. Signed before any work begins.
Common questions
How much does a pentest cost?
It depends on the scope: the number of applications, the size of the network, the access mode. A small web app and a large infrastructure differ many times over. After a short conversation we give a fixed price and timeline; we do not publish prices on the site because without scope they mislead.
Will you break something during the pentest?
We work within agreed boundaries and rules: no DoS, no data destruction, destructive actions only in a test environment and after separate permission. We warn about risky steps in advance.
How long does the work take?
A pentest of one application: one to two weeks including the report. Infrastructure: two to four weeks. A bug sweep: from a few hours to a day. ISO 27001 preparation: three to nine months depending on the starting point.
Do you sign an NDA?
Yes, before any work begins. We can sign your template or provide ours.
Can I contact you anonymously?
Yes. The form has a confidential mode: no name or phone, only a Signal or Session handle. For a bug sweep we arrange a meeting without witnesses.
Do you work outside Ukraine?
Yes, with EU customers remotely for pentesting and compliance, and on site for sweeps by arrangement.
Do you issue a certificate after a pentest?
We issue a report and a letter confirming that the testing and the retest were performed. An ISO 27001 certificate is issued only by an accredited body; we prepare you for it.
What happens if you find a bug?
We do not touch the device until you decide: we record it, photograph it and write a protocol. Then either removal or, on lawyers' advice, involving law enforcement while preserving evidence.
Write to us
The message goes straight to our Telegram. Nothing stays on the server.
Telegram
