Company / Methodology
How our engagements run
The frameworks our work maps to and the flow every engagement follows — the same facts published on our service and trust pages, gathered in one place.
Penetration testing & security testing
Testing is aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115, with retest included as standard — remediation is verified on retest and the report updated to “remediated and retested.”
- 01
Scope
A scoping call with the testers themselves — targets, rules of engagement, and what evidence you need out.
- 02
Test
Manual assessment aligned to OWASP, PTES, and NIST SP 800-115, with daily contact for critical findings.
- 03
Report
Findings ranked by exploitability and impact, each with reproduction and remediation guidance.
- 04
Retest
Verification of fixes and an updated report — the cycle then repeats on your release cadence.
Quality engineering
Requirement-traced test design ranked by risk, executed with disciplined evidence capture. Where accessibility is in scope, work is assessed against WCAG 2.2 AA, EN 301 549, and Section 508.
- 01
Scope
Understand the product, the release, and where failure hurts most.
- 02
Design
Test charters and cases ranked by risk, reviewed with your team.
- 03
Execute
Time-boxed cycles with daily defect triage and clear severity calls.
- 04
Report
A release-readiness view: what was covered, what was found, what remains open and why it matters.
How every engagement is governed
Under NDA
Every engagement runs under a mutual non-disclosure agreement. Scope, rules of engagement, and communication channels are agreed before any testing begins.
Methodology & retest
Testing is aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115. Remediation is verified on retest and the report updated to “remediated and retested.”
Personnel security
Engineers who handle client data sign NDAs and undergo background checks. The people who scope your engagement are the people who run it — no anonymous offshore bench.
Data handling
Findings and reports are shared only through the channels agreed at scoping and retained only for the period needed to deliver and support the engagement. Storage, encryption, retention, and destruction specifics are set in your service agreement.
Company facts, certifications held by our engineers, and the vendor due-diligence process are documented on the Trust & Company Facts page.
Ready to scope the work?
A 30-minute call with the engineers who will do the testing — not a sales gate.