What to expect

How an engagement
works, start to finish

No mystery, no surprises. Every engagement follows the same disciplined path — you authorise the work in writing before anything is touched, and you get proof and a fix at the end. Here's exactly how it goes.


The process

Five steps, every time

STEP 01

Scoping call

A direct conversation with me — no sales layer. We talk through what you're protecting, what worries you, and what "done" looks like. Free, and with no obligation to proceed.

STEP 02

Proposal & written authorisation

You get a clear proposal and a Rules-of-Engagement document: exact scope, targets, timing and boundaries. Nothing is touched until you sign it. Authorisation in writing, always.

STEP 03

Controlled testing

I test within the agreed window and scope — with a live contact, source IPs you can allow-list, and an emergency stop you can call at any time. Exploitation goes only as far as it needs to prove impact.

STEP 04

Report that gets fixed

Every finding comes with a working proof-of-concept, severity ranked by real business impact, reproduction steps, and a fix written for the developers who own it — plus an executive summary.

STEP 05

Retest

Once you ship the fixes, I verify them. A finding closes when the risk is genuinely gone — not when a ticket is marked resolved.

What you can count on

The same standards, every engagement

01 / AUTHORISED

Permission first

I only test what you own or are authorised to have tested, under signed scope and Rules of Engagement. No exceptions.

02 / CONFIDENTIAL

Your findings stay yours

What I find on your systems goes to you, privately. No leverage, no public write-ups of your environment.

03 / EVIDENCE-LED

Proof, not noise

If I can't reproduce it, I don't report it. No scanner dumps, no inflated severity to pad a report.

What I'll need from you

To start cleanly

01

Authorisation & scope

Confirmation you can authorise testing of the targets, and a signed Rules-of-Engagement document before work begins.

02

Access & contacts

Any credentials or access needed for the agreed approach, plus a technical contact and an emergency contact during the window.

03

Backups in place

Working backups and recovery for in-scope systems — standard good practice before any security testing.

Ready to start?

Book a scoping call and I'll tell you honestly whether and how I can help.

Start a conversation View services