Skip to main content
// Methodology

How We Test

Rigor is what separates a report you can act on from a scanner dump. Every engagement follows a repeatable, standards-based methodology — authorization first, manual validation always, evidence throughout.

// Testing Lifecycle

Five Phases, Aligned to Global Standards

Built on NIST SP 800-115 and the Penetration Testing Execution Standard (PTES).

01

Planning & Authorization

Define objectives, targets, and boundaries in writing before any hands-on work begins.

Activities

  • Scope definition and asset confirmation
  • Signed rules of engagement and authorization
  • Testing windows and emergency contacts
  • Success criteria and reporting expectations

Standards

NIST SP 800-115PTES: Pre-engagement
02

Discovery & Enumeration

Map the real attack surface — what exists, what is exposed, and what matters most.

Activities

  • Passive reconnaissance and OSINT
  • Service, port, and technology fingerprinting
  • Application and API surface mapping
  • Business-criticality prioritization

Standards

OWASP WSTGMITRE ATT&CK: ReconnaissanceCIS Controls
03

Analysis & Validation

Identify weaknesses and manually validate them — every material finding is proven, controlled, and in-scope.

Activities

  • Weakness identification against OWASP / ASVS
  • Manual verification to eliminate false positives
  • Controlled, authorized proof-of-concept
  • Impact and exploitability analysis

Standards

OWASP Top 10 / ASVSOWASP LLM Top 10MITRE ATT&CKCVSS v3.1
04

Reporting

Translate findings into a clear risk narrative with reproducible evidence and prioritized fixes.

Activities

  • Risk-ranked findings with CVSS scores
  • Reproducible evidence and ATT&CK mapping
  • Developer-ready remediation guidance
  • Executive summary for decision-makers

Standards

CVSS v3.1MITRE ATT&CK mappingNIST SP 800-115: Reporting
05

Remediation & Retest

Support the fix, verify it, and establish continuous assurance so security becomes a state, not an event.

Activities

  • Remediation guidance and pairing
  • Retest of fixed findings
  • Continuous monitoring options
  • Lessons-learned and posture improvement

Standards

NIST CSF 2.0MITRE D3FENDContinuous assurance
// Frameworks We Align To

Standards Coverage

We measure our work against the references the industry trusts.

OWASP Top 10 & ASVS

Web/API weakness classes and verification levels

OWASP WSTG

Step-by-step web application testing procedures

OWASP Top 10 for LLMs

AI/LLM application risks (prompt injection, data leakage)

NIST SP 800-115

Technical guide to security testing and assessment

PTES

End-to-end penetration testing execution standard

MITRE ATT&CK

Adversary tactics and techniques for emulation and mapping

MITRE ATLAS

Adversarial threat landscape for AI systems

MITRE D3FEND

Defensive countermeasures mapped to attacks

CIS Benchmarks & Controls

Hardening baselines and prioritized safeguards

CVSS v3.1

Consistent, transparent vulnerability severity scoring

// What We Stand For

Principles That Never Bend

The commitments that hold across every engagement, regardless of scope.

Authorization first, always

No testing begins without signed scope and rules of engagement. Out-of-scope systems are never touched.

Manual validation over scanner dumps

Automated tooling accelerates discovery, but a human validates every material finding. We deliver signal, not noise.

Evidence-based and reproducible

Each finding ships with the evidence and steps to reproduce it — so your team can confirm and fix with confidence.

Least-impact testing

We favor the safest technique that proves the risk, and coordinate closely to avoid disrupting your operations.

Business risk, not just technical severity

Findings are prioritized by real impact to your business, not raw CVSS alone — so you fix what matters first.

Confidentiality by default

Findings, evidence, and access are handled as strictly confidential, with disciplined data handling throughout.

See the methodology in action

Explore the services this methodology powers, or start a scoping conversation to define the right engagement for your systems.