Skip to content

Company / Methodology

How we deliver, phase by phase

Every engagement moves through the same seven phases, from the first conversation to standing support. Each one below shows the work, what you receive, your part in it, and how both sides know it is done: the same facts published on our service and trust pages, and what you can commit to an auditor before you sign.

The seven phases of an engagement

A two-week assessment and a three-year program pass through the same phases; only the cadence changes. Expand any phase for the detail.

  1. DiscoverUnderstand the product, the release, and where failure hurts most.

    Activities

    A first conversation with the engineers who would deliver the work: your product, your architecture, and the deadline behind the request.

    Deliverables

    A shared view of where failure hurts most, and of which evidence will satisfy the auditor, the customer, or the board that asked.

    Your involvement

    Bring the audit date, the security questionnaire, or the release plan. We work backwards from what you need to prove.

    Success criteria

    Both sides can name the risk in play and the artifact that will settle it.

  2. ScopeTargets, rules of engagement, and evidence out, agreed in writing.

    Activities

    A scoping call with the testers themselves. Targets, rules of engagement, and the evidence you need out are agreed in writing.

    Deliverables

    Written scope, signed rules of engagement, agreed communication channels, and a mutual non-disclosure agreement before any testing begins.

    Your involvement

    You set scope and sign the rules of engagement. The people on this call are the people who will run the work.

    Success criteria

    Everything the engagement depends on exists on paper before the first test runs.

  3. EngineerSenior engineers run the work, with daily contact.

    Activities

    Security testing runs manually, aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115. Quality engineering runs risk-ranked test charters in time-boxed cycles.

    Deliverables

    Defects triaged daily with clear severity calls, and automation built in your CI on frameworks your team already uses.

    Your involvement

    Daily contact. Critical findings reach you the day they are demonstrated; nobody waits for the report to learn bad news.

    Success criteria

    The agreed scope is exercised in full and nothing urgent sits waiting in a draft report.

  4. ValidateFindings demonstrated, ranked, and written to be acted on.

    Activities

    Every finding is demonstrated with reproduction steps and evidence of impact, then ranked by exploitability and impact rather than scanner scores.

    Deliverables

    An executive summary your board can read and technical findings your engineers can act on without a follow-up meeting.

    Your involvement

    You review each demonstrated finding with its evidence. Remediation guidance arrives ordered, so your team knows what to fix first.

    Success criteria

    Nothing in the report is theoretical. Anyone on your team can reproduce a finding from the steps written down.

  5. RetestFixes verified, the report updated.

    Activities

    Your team fixes on its own schedule. We verify each fix on retest and update the report to “remediated and retested”, the phrase auditors look for.

    Deliverables

    A retest-verified final report you can hand to auditors and enterprise customers as it stands.

    Your involvement

    Tell us when the fixes land. The retest checks them against the original reproduction steps.

    Success criteria

    Remediation is verified rather than assumed, and the final report says so.

  6. Transfer knowledgeThe capability becomes your team's.

    Activities

    Handover documentation, pairing sessions, and, where the engagement calls for it, secure-coding workshops built around the findings from your own systems.

    Deliverables

    The framework, the documentation, the CI integration, and a maintenance playbook. You own all of it.

    Your involvement

    Your engineers pair with ours during handover, so the first person to maintain the work has already run it.

    Success criteria

    Handover is an explicit exit criterion: what we built keeps working after we leave.

  7. SupportRepeat on your cadence, co-run, or hand over.

    Activities

    The cycle repeats on your release cadence, or we stay on as your managed team across testing, automation, or SOC coverage, under the same governance either way.

    Deliverables

    Evidence that stays current: refreshed reports each cycle, regression packs that grow with every finding, and detection content built from what testing proved exploitable.

    Your involvement

    You choose the shape: run by us, co-run with your team, or handed over entirely once it is self-sustaining.

    Success criteria

    Next quarter's questionnaire meets this quarter's report.

The frameworks the work maps to

Penetration testing & security testing

Testing is aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115, with retest included as standard: remediation is verified on retest and the report updated to “remediated and retested.”

Quality engineering

Requirement-traced test design ranked by risk, executed with disciplined evidence capture. Where accessibility is in scope, work is assessed against WCAG 2.2 AA, EN 301 549, and Section 508.

How every engagement is governed

Under NDA

Every engagement runs under a mutual non-disclosure agreement. Scope, rules of engagement, and communication channels are agreed before any testing begins.

Methodology & retest

Testing is aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115. Remediation is verified on retest and the report updated to “remediated and retested.”

Personnel security

Engineers who handle client data sign NDAs and undergo background checks. The people who scope your engagement are the people who run it. No anonymous offshore bench.

Data handling

Findings and reports are shared only through the channels agreed at scoping and retained only for the period needed to deliver and support the engagement. Storage, encryption, retention, and destruction specifics are set in your service agreement.

Company facts, certifications held by our engineers, and the vendor due-diligence process are documented on the Trust & Company Facts page. Evaluating vendors? Our guide to choosing a penetration testing vendor turns these facts into the checklist we’d use ourselves.

Ready to scope the work?

A 30-minute call with the engineers who will do the testing, not a sales gate.