Skip to main content

About

A small practice of practitioners, not a body shop.

Every engagement here is led by a consultant who has been doing this work for years. We keep the practice deliberately small, because the alternative is staffing engagements with people who are not right for them.

01Expertise

Depth in five disciplines, and honesty about the rest.

Consultants are staffed on the discipline they actually specialise in. Where a request falls outside what we do well, we say so and, where we can, point you at someone who does it properly.

  • 01

    Web, API and mobile

    Consultants who have spent their careers in application security: authorisation logic, session handling, the full injection family, and the business logic flaws that automated tooling is structurally incapable of finding.

  • 02

    Internal and Active Directory

    Domain escalation paths, certificate services abuse, delegation and relay issues, credential exposure, and lateral movement across networks that were supposed to be segmented.

  • 03

    Cloud and container platforms

    Identity boundaries across AWS, Azure and GCP, Kubernetes RBAC and workload isolation, and the build pipelines that quietly bridge a developer laptop into production.

  • 04

    Adversary simulation

    Operators who build their own infrastructure and tooling, run controlled social engineering, and work patiently inside monitored environments rather than burning access on day one.

  • 05

    Exploit research

    Memory corruption, unsafe deserialisation, protocol reversing and firmware analysis, with working proof-of-concept development against bespoke and vendor software.

  • Consultants split their year between client engagements and protected research time, which is where our tooling and most of our published notes come from.

02Methodology

Standards set the floor. The interesting work happens above it.

Recognised methodologies make coverage auditable and comparable between cycles. They are a baseline, not a script, and no standard understands your business logic.

  • Manual first, automation second

    Tooling is used to widen coverage, never to produce findings. Every issue in a report was confirmed by a consultant who understood why it worked.

  • Aligned to standards, not limited by them

    PTES, the OWASP testing guides and NIST SP 800-115 set the floor for coverage. What matters to your particular system usually sits above that floor, and that is where most of the engagement is spent.

  • Evidence behind every claim

    Each finding ships with the request, the response, the payload and the reproduction steps. Nothing is asserted that your team cannot reproduce on their own machine.

  • Impact over finding counts

    A long report is not a good report. We rank by what an attacker can actually do in your environment, and we say plainly when a scored vulnerability is not exploitable in context.

Reference standards

PTES
Penetration Testing Execution Standard
WSTG
OWASP Web Security Testing Guide
ASVS
OWASP Application Security Verification Standard
ATT&CK
MITRE adversary tactics and techniques
800-115
NIST technical guide to security testing
CIS
CIS platform hardening benchmarks

03Certifications

Certified in the disciplines we are staffed on.

Certifications are evidence of a baseline, not a substitute for experience. We list them because procurement teams ask, and because the study time is paid for and protected.

  • OSCP

    Offensive Security Certified Professional

  • OSEP

    Offensive Security Experienced Penetration Tester

  • OSWE

    Offensive Security Web Expert

  • OSED

    Offensive Security Exploit Developer

  • CRTO

    Certified Red Team Operator

  • CRT

    CREST Registered Penetration Tester

  • GXPN

    GIAC Exploit Researcher and Advanced Penetration Tester

  • GWAPT

    GIAC Web Application Penetration Tester

What we will not do

  • We do not resell scanner output as a penetration test.
  • We do not test outside written scope, however tempting the adjacent target looks.
  • We do not pad reports with informational findings to make the deliverable look heavier.
  • We do not take an engagement we are not staffed to run properly in the window you need.

Start here

Work with the people who will actually run the test.

Scoping calls are taken by the consultant who will lead the engagement, not by an account manager. You will know exactly who is doing the work before you sign anything.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now