Skip to content

Services

Four services. One team. Nothing subcontracted.

Every engagement is run by the same senior practitioners who scoped it. We report critical findings the hour we confirm them, and we retest everything we report.

Engagement shape
Fixed scope and fixed price, agreed in writing before any testing begins.
Who does the work
The practitioners you meet during scoping. No handover to a junior after signature.
After delivery
A walkthrough with your engineers and a retest of every finding, included.

Service 01

Penetration Testing

A time-boxed, goal-oriented attack against the systems you nominate. We work towards an agreed objective rather than down a checklist, and we tell you the moment something serious surfaces instead of saving it for the report.

What is included

  • External and internal network testing
  • Web application and API testing, authenticated and unauthenticated
  • Cloud configuration review across AWS, Azure and Google Cloud
  • Authentication, session and authorisation logic testing
  • Business logic abuse, not only the injection classes a scanner knows
  • Exploit chaining towards an objective you define before we start

How it runs

  1. Scoping

    We agree the targets, the objective, the rules of engagement and who to call if we find something that cannot wait.

  2. Reconnaissance

    Attack surface mapping across your estate, credentialed wherever credentials make the test sharper rather than slower.

  3. Exploitation

    Manual testing with tooling in a supporting role. Critical findings are reported the hour we confirm them, not in week three.

  4. Report and retest

    A written report, a walkthrough with your engineers, and a retest of every finding once you have fixed it.

You receive

  • Technical findings report with reproduction steps and evidence
  • Executive summary written for people who will not read the technical report
  • Prioritised remediation plan with rough effort estimates
  • Attestation letter you can share with customers and auditors
  • One retest of all findings, included, within ninety days
Typical duration
Two to four weeks
Best for
Teams facing a customer security review, an audit, or their first serious test
Available from
Starter and above
Discuss this engagement

Service 02

Security Consulting & Risk Assessments

An honest assessment of your risk, written without the padding that makes most risk reports go unread. We spend time with your engineers and your leadership, then tell you what we would fix first if it were our company.

What is included

  • Threat modelling against your real architecture and data flows
  • Risk register built from your systems rather than a generic template
  • Control gap analysis mapped to SOC 2, ISO 27001, HIPAA or CIS
  • Vendor and third-party risk review
  • Roadmap sequenced by risk reduced per unit of engineering effort
  • Budget and hiring guidance for the next twelve months

How it runs

  1. Discovery

    Interviews with engineering, operations and leadership, plus a read of the architecture as it is rather than as it was drawn.

  2. Modelling

    We map the assets worth protecting, who would want them, and the routes that currently exist to reach them.

  3. Prioritisation

    Every risk is scored against likelihood, impact and the cost of fixing it, so the ordering survives an argument.

  4. Roadmap

    A sequenced twelve-month plan, presented to your leadership team with the reasoning intact.

You receive

  • Risk register your team can maintain after we leave
  • Threat model diagrams for the systems that matter most
  • Control gap matrix against your chosen framework
  • Twelve-month security roadmap with owners and effort bands
  • Leadership briefing, delivered live and left behind as a document
Typical duration
Three to six weeks
Best for
Companies deciding where to spend a security budget for the first time
Available from
Growth and above
Discuss this engagement

Service 03

Security Architecture & Hardening

Design and implementation work done alongside your team. We review what you have, propose what it should become, and stay involved while it is built, so the design survives the first sprint that touches it.

What is included

  • Architecture and design review for new and existing systems
  • Identity and access design, covering single sign-on, MFA and least privilege
  • Network segmentation and zero-trust access patterns
  • Cloud baselines written as code, with drift detection
  • Secrets management, key rotation and certificate lifecycle
  • Secure defaults built into your build and deployment pipeline

How it runs

  1. Review

    We read the architecture, the infrastructure code and the parts of the estate nobody has looked at since it was built.

  2. Design

    A target state your team agrees with, split into changes that can ship independently rather than one rewrite.

  3. Implementation support

    We pair with your engineers, review pull requests, and write the modules nobody has time to write.

  4. Verification

    We test the result the same way we would test a client we had never met, and hand over the tooling to keep it honest.

You receive

  • Architecture review with findings ranked by blast radius
  • Target-state design documents and diagrams your team will actually use
  • Infrastructure-as-code baselines and guardrails
  • Pipeline controls that block a whole class of regression
  • Handover session and documentation for the engineers who inherit it
Typical duration
Four to twelve weeks, or ongoing
Best for
Teams rebuilding, migrating cloud, or scaling past the architecture that got them here
Available from
Growth and above
Discuss this engagement

Service 04

Incident Readiness & Response Planning

The worst time to design an incident process is during an incident. We build the plan, prove it with an exercise, and make sure the logs you will need already exist before you need them.

What is included

  • Incident response plan written around your team, roles and tooling
  • Detection and logging review across endpoints, cloud and applications
  • Severity model, escalation paths and on-call responsibilities
  • Tabletop exercises run against scenarios drawn from your own estate
  • Communication templates for customers, regulators and staff
  • Retainer options for hands-on response when something real happens

How it runs

  1. Assessment

    What you can currently see, what you can prove, and how long it would take you to answer the questions a breach raises.

  2. Plan

    A plan short enough to be read at three in the morning, with runbooks for the scenarios most likely to reach you.

  3. Exercise

    A facilitated tabletop with your real on-call people, run without warning them what the scenario is.

  4. Refine

    We fix what the exercise broke, close the logging gaps it exposed, and leave you able to run the next one yourselves.

You receive

  • Incident response plan and severity model
  • Runbooks for your most likely scenarios
  • Logging and detection gap report with a prioritised fix list
  • Tabletop exercise findings and a recording of the session
  • Customer, regulator and internal communication templates
Typical duration
Two to five weeks
Best for
Teams with a plan nobody has read, or no plan at all
Available from
Starter and above
Discuss this engagement

Not sure which one

Most people start with a conversation, not a service

Describe the situation and we will tell you which of these is the right shape, or that none of them is. Scoping calls are free and take about half an hour.