Services

Five practices. 70 services.

Offensive security, governance and compliance, AI consulting, managed services and training — delivered by senior practitioners and amplified by our own platform. The people who scope your work are the people who deliver it.

How it fits together

Two halves of the same job.

Testing tells you what an attacker can actually do. Compliance tells you what you have committed to doing about it. Run separately they produce two registers that disagree by the second year, which is why a great many organisations can show a clean audit and a live vulnerability at the same time.

We run them against one register. A penetration test finding lands as evidence against the control it breaks, and a control gap gets tested rather than asserted. That is the whole argument for buying both from one firm — not the discount.

Security testing 9 services Compliance 8 frameworks findings evidence One risk register, not two a test finding and a control failure are the same object

How We Work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, whatever the service.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Everything We Deliver

All 70 services, by practice line.

The complete list. If what you need is not here, ask — we will tell you honestly whether it is something we should take on.

Offensive Security & VAPT

Find it before somebody else does. Application, API, mobile, network, cloud and code testing, run by people who exploit what they find and prove it.

  • Vulnerability Assessment
  • Penetration Testing
  • External Attack Surface Management
  • Web Application Security Testing
  • Mobile Application Security
  • API Security Testing
  • Cloud Security Assessment
  • Network Security Assessment
  • Active Directory Assessment
  • Red Team Exercises
  • Purple Team Engagement
  • Security Architecture Review
  • Secure Code Review
  • Threat Modeling
  • Zero Trust Readiness Assessment
  • Continuous Security Monitoring
  • Wireless Security Assessment
  • Incident Response Readiness
  • Digital Forensics Support
  • Ransomware Readiness Assessment
  • Third-Party Security Assessment
  • Supply Chain Security Review
  • IoT & Embedded Device Testing

Questions

Choosing a service — answered.

Which service do we need first?

If you have never had an independent test, start with an external network assessment and a penetration test of your most important application. Between them they cover how somebody gets in from the internet and what they can do once they reach your product, which is where the overwhelming majority of real incidents begin. If a customer or auditor has asked for something specific, buy that first — the deadline is real and the rest can follow.

Can we combine services into one engagement?

Yes, and it is usually cheaper than buying them separately. Application testing, API testing and a secure code review of the same system share a great deal of context, so running them together costs meaningfully less than three separate engagements and produces a better report because the findings cross-reference each other.

Do you work on retainer or project by project?

Both. Most clients start with a project — a defined test with a fixed scope and price — and move to a retainer once they want continuous coverage between annual tests. The managed service exists precisely because an annual test leaves fifty-one weeks unwatched.

How quickly can you start?

Typically within two to three weeks of a signed scope, and faster where there is a genuine deadline. Tell us the date you are working to during scoping and we will tell you honestly whether we can meet it rather than agreeing and then explaining later.

What if we need something not on this list?

Ask. We will tell you plainly whether it is something we should take on, and if it is not, we will point you at somebody who should. Taking work we are not the right firm for is a bad trade for both sides.

Next step

Not sure where to start?

Most people are not, and it is the most common reason for the call. Describe the situation in thirty minutes and we will tell you which piece of work actually answers your question — including when the answer is a smaller one than you expected.