Home / Trust & Compliance
TRUST

Security you can verify.

We ask clients to trust us with their most sensitive environments. That trust is earned by aligning to recognized standards, disciplined controls, and a way of working you can audit - not promises.

Standards

Standards we operate to.

We align our work to the standards that set the bar for offensive security and information governance - and hold our own house to the same scrutiny.

CREST

Independent accreditation of penetration testing and red-team services to a recognized professional standard.

Offensive Security

OSCP / OSCE

Hands-on, exploitation-focused certifications held by our operators, earned through practical compromise rather than multiple choice.

ISO/IEC 27001

ISO 27001

International standard for information security management, governing how we handle our own and our clients' data.

SOC 2 Type II

SOC 2

Independent attestation of our security, availability, and confidentiality controls over a sustained period.

PCI DSS

QSA

Qualified Security Assessor capability for testing and validating environments that store or process payment-card data.

CHECK

NCSC

UK National Cyber Security Centre scheme for delivering penetration testing to public-sector and critical national infrastructure.

Research by our team has found & disclosed vulnerabilities in
Better Authn8nSAPTwilioFusionAuth
Engagement security

How we handle your access, your data, and your findings.

An offensive engagement gives us privileged insight into your organization. These commitments govern every hour of that access - written into our contracts, not just our culture.

Confidentiality, contractually

Every engagement begins under a mutual NDA. Scope, findings, and the very existence of the work are confidential by default - and we will sign your paper, not just ours.

Least-privilege access

We request the minimum access required to achieve the agreed objectives, time-box it to the testing window, and revoke credentials the moment the engagement closes.

Secure handling of findings

Evidence, exploit code, and reports live in encrypted, access-controlled stores. Deliverables are shared over channels you approve, never untracked email attachments.

Responsible disclosure

Critical exposures are escalated in real time during the engagement - not held for the final report. Anything touching third parties follows a coordinated disclosure process.

Defined data retention

Test data and artifacts are retained only as long as your contract requires, then securely destroyed. You receive written confirmation when disposal is complete.

Vetted consultants

Every operator is background-checked, certified, and bound by ongoing confidentiality obligations. The people in your environment are the people named in your statement of work.

Methodology

Frameworks behind every engagement.

OWASP

The open standard for application and API security testing.

We test web and API targets against the OWASP Testing Guide and the Top 10 risk categories, treating them as a coverage floor rather than a checklist. The OWASP Application Security Verification Standard gives our reports a shared, measurable baseline that maps cleanly to your developers' frame of reference. For APIs, we work to the OWASP API Security Top 10, which captures the authorization and exposure risks unique to that surface.

  • Coverage aligned to the OWASP Web and API Security Top 10
  • Verification depth structured around ASVS levels
  • Methodology drawn from the OWASP Testing Guide
  • Findings mapped to language your engineers already use

MITRE ATT&CK

The shared taxonomy of real-world adversary tactics and techniques.

Every red-team action and hunting hypothesis is mapped to MITRE ATT&CK, so results are expressed in the same language your detection engineering and threat intelligence teams already use. We emulate the specific techniques associated with the threat groups relevant to your sector, then measure your detection coverage technique by technique. The matrix becomes a scorecard: a precise map of which adversary behaviors you can see and which you cannot.

  • Operations mapped technique-by-technique to the ATT&CK matrix
  • Threat-group emulation based on documented adversary behavior
  • Detection coverage measured against specific techniques
  • Purple-team tuning driven by ATT&CK gaps

NIST

Federal guidance for risk-based security testing and assessment.

We align technical testing with NIST SP 800-115, the standard methodology for security testing and assessment, and frame results against the NIST Cybersecurity Framework so leadership can read them in risk terms. This makes our findings straightforward to slot into existing governance, audit, and risk-management processes. Where relevant, we reference the SP 800-53 control families that a finding implicates.

  • Technical methodology grounded in NIST SP 800-115
  • Results framed against the Cybersecurity Framework functions
  • Findings tied to relevant SP 800-53 control families
  • Output structured for existing governance and audit processes

PTES

The end-to-end standard for how a penetration test is run.

The Penetration Testing Execution Standard defines the lifecycle our engagements follow, from pre-engagement scoping through intelligence gathering, threat modeling, exploitation, post-exploitation, and reporting. Following PTES keeps engagements consistent and rigorous regardless of who runs them, and ensures the unglamorous phases - scoping and post-exploitation analysis - get the same discipline as exploitation. It is the connective tissue between the technique-level frameworks and a coherent engagement.

  • Consistent engagement lifecycle from scoping to reporting
  • Structured intelligence gathering and threat modeling
  • Disciplined post-exploitation and impact analysis
  • Repeatable rigor independent of the individual tester
Get ahead of zero

Ready to see yourself the way an adversary would?

Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.

Book a free scoping call