FAQ
Frequently asked questions
If your question is not here, write to us. We answer if we can help, and we say so if we cannot.
How is this different from a vulnerability scan?
A scanner returns a list of candidates: things that might be wrong. We use those tools to cover the surface, and then we try to exploit every candidate by hand.
Whatever we cannot reproduce stays out of the report, and whatever goes in comes with its proof of concept.
How much does it cost?
We do not publish rates because the work changes a great deal with scope: a single domain is not an internal network with Active Directory.
We agree the scope in writing first, and the price is given for that specific scope, before we start.
What do you need from us to start?
Written authorisation from the owner of the systems and an agreed scope: which domains, ranges or applications are in and which are out. Without that, nothing is touched.
Depending on the service, also: one user per role for the web application pentest, or a machine inside the network with an ordinary employee’s credentials for the internal test.
Are you a certification body? Does the report count for ISO 27001, ENS or NIS2?
We are not a certification body or an accredited organisation, and the report does not certify compliance with any standard.
What it documents is what was tested, which vulnerabilities were verified and how to fix them. If a compliance process asks you for technical evidence, that is the information you can provide; whether you comply is decided by whoever audits that standard.
Could you take down a production system?
Any test against a real system carries risk, which is why it is agreed beforehand: the scope sets what can be touched, from where and when.
Exploitation is controlled. The aim is to show that the flaw exists, not to cause the damage it would allow. If there is an equivalent pre-production environment, working on it can be agreed.
How long does it take?
It depends on the scope, for the same reason as the price. Dates are agreed together with it, before we start.
What do we get at the end?
A report with every verified vulnerability: the proof of concept that reproduces it, the real impact and the concrete fix. It is written so that whoever decides can follow it and whoever writes the code can apply it.
Once you have fixed things, we can come back with a retest to check that the fixes hold.
If you use AI, how are you different from an automated platform?
We use AI to cover ground: enumerating the surface and flagging candidates faster than one person would alone.
It does not decide what a vulnerability is. Every finding is verified by hand by a person, and only that goes into the report.
What happens to the information from our systems that you see?
During an engagement we may access sensitive information, including personal data of third parties. That access is governed before we start by a data processing agreement, with the scope, the security measures and the deletion periods in writing.