How we work
Careful by design, defensible by default.
The way we work is the product as much as what we find. These principles are not marketing — they are the controls that keep the work safe, legal and trustworthy.
Authorised, always
Every engagement is contracted. Any active work requires a written, agreed scope and touches only the systems inside it. Out-of-scope addresses are never even stored — only a count of what was set aside.
Passive by default
We prefer observation to probing. Our passive methods cannot disrupt a running system, which is what makes them safe for OT and critical processes. Active checks are the exception, scoped and agreed — never the default.
Identification, not exploitation
We prove the door is unlocked; we do not walk through it. We confirm a vulnerable version and the vendor advisory, and stop there. No exploitation without a separate, signed engagement — and we never claim “confirmed vulnerable” from the outside.
Honest coverage
Every finding states the observation window, what was checked, and what could not be seen. The absence of a finding is not proof of absence, and we say so. A low-confidence observation is never dressed up as a certainty.
Evidence you own
Your findings are yours. We hold metadata, not payloads, to keep everyone’s exposure low — and on offboarding you get a clean export of your archive. It is your evidence, not our lock-in.
We found it — we say so plainly
A finding is “we found the gap”, never “we closed it”. When remediation follows, it is described as exactly that. We would rather under-claim and be trusted than over-claim and be caught.
A typical engagement
From first look to dated evidence.
- Scope & authorisation. We agree in writing what is in scope and what we may do. Nothing starts before this.
- Passive external mapping. We map your internet-facing exposure from public sources — no packets to your systems.
- Range sweep & identification. Within scope, we complete the picture and identify versions and services, safely.
- Findings & evidence pack. You get an asset register, a clear findings report, and a dated evidence pack mapped to the frameworks.
- Remediation, if you want it. Where the gap is a network-security one, we can help close it — described honestly as remediation.
- Repeat runs. Later runs show what changed, so you can evidence that the measures are working over time.