Scope & Delivery

Every engagement is quoted as a fixed-price project based on the systems in scope, the depth of testing required, and the access available. Before testing begins, you receive a written scope defining the targets, methodology, deliverables, timeline, and price.

What shapes the scope

The required effort depends on the size and complexity of the attack surface, the number of user roles and trust boundaries, the available documentation and access, the technologies involved, and the depth of testing required.

We focus the scope on the systems and workflows where a meaningful compromise would have the greatest impact.

What is included

Every engagement includes senior-led manual testing, a clear technical report, remediation guidance, a findings review, and retesting after remediation.

If testing uncovers vulnerabilities in a third-party product, we can coordinate responsible disclosure with the affected vendor.

Pricing

Pricing is based on the scope and complexity of each engagement. A fixed fee is provided once the scope is understood. If the scope needs to be adjusted, we can prioritize the highest-risk applications, workflows, or trust boundaries rather than reduce the depth of the testing. Our standard billing structure is 50% at engagement confirmation, with the remaining 50% due on delivery.

Start a conversation

Tell us what you want tested, your preferred timeline, and any important technical or business constraints. We’ll respond with the questions needed to prepare a scope.

Let’s Talk »