What's included and what you receive at the end.
An engagement with a scope, a schedule and a final report, designed to answer a specific question. Everything in the report has been discussed beforehand: the final document confirms, it does not reveal.
What's included
- Reconnaissance and mapping of the exposed surface
- Vulnerability analysis with manual validation
- Controlled exploitation, with no denial of service
- Review of web applications and APIs (OWASP Top 10)
- Remediation plan prioritised by risk
Deliverables
- Executive report
- Technical report
- Results presentation session
- Retest of findings
How we work
The same method on every project, so results are comparable with each other and over time. Every finding is scored with CVSS and put in context according to the affected asset, how easy it is to exploit and the real impact on the business.
Scope and rules of engagement
Objectives, assets, time windows, emergency contacts and formal written authorisation.
Reconnaissance
We map the attack surface and inventory the assets, both known and discovered.
Analysis and controlled exploitation
We validate every finding manually, with no denial of service and no unnecessary data extraction.
Report and presentation
An executive report for management and a technical report for the team, with a prioritised remediation plan.
Retest and follow-up
We verify the fixes and update the status of every finding in DARKFORGE.
Guarantees across all services
Authorisation and contract
No test starts without express written authorisation and a signed scope.
Confidentiality
Non-disclosure agreement, safekeeping of information and secure deletion at closure.
No impact on operations
Agreed time windows, no denial of service and a permanent emergency contact.
Data in the European Union
Evidence and reports hosted and processed in the EU, on our own platforms, aligned with NIS2, DORA, ENS, ISO/IEC 27001 and GDPR.
Related services.
Services are combined into annual programmes with a single point of contact and a shared calendar, and any of them can be contracted as PTaaS with continuous testing and unlimited retesting.
Let's talk about your security.
Request a no-obligation initial assessment and we will propose the service that best fits your organisation.