Most tests end with a PDF and an invoice. Ours ends when the findings are closed. We test your website, your web application and your external surface with your written authorisation, demonstrate every real finding, then sit with you — or your developer — and harden it. Then we test it again, free, to prove it is actually fixed.
Authorised testing only · Fixed scope, fixed price · Re-test included · Call or text (940) 281-6672
Anyone can run a scanner and hand you two hundred results. The work that matters is proving which ones a real attacker could actually use, ranking them by what they would cost you, and then closing them. A finding we cannot demonstrate does not go in the report as a finding — it goes in as an observation, clearly marked.
And a control nobody has tested is not a control. We check whether the thing works, not whether it is documented — the backup that has never been restored, the alert channel nobody has ever received a message on, the login page that rate-limits in theory.
.env and .git directoriesNot sure which fits? That is what the scoping call is for. Prices are starting points — the scope drives the number, and you get it in writing before anything begins.
We test only with your written authorisation, only the assets you name, and only in the window you agree. If your site is hosted by a third party we get their sign-off too, because testing someone else's infrastructure without it is a crime rather than a service.
We do not test destructively. No denial-of-service, no data destruction, no social engineering of your staff unless you specifically ask for it and scope it separately. If we find something critical mid-test we stop and phone you the same hour rather than saving it for the report.
Findings are yours. We hold no copy beyond the engagement plus the re-test window, and we certify deletion in writing when it closes.
A short call to understand what you have and what you are worried about. You get a written scope and a fixed price before anything is touched — and an honest answer if a test is not what you need yet.
Request a scope & quoteOr call the Security Architect directly — (940) 281-6672
A penetration test is an authorized, hands-on attempt to find and prove the weaknesses a real attacker could actually exploit — across your website, web application, and internet-facing systems. A scanner lists hundreds of possible issues; a test proves which ones are real, ranks them by what they would cost you, and marks anything it cannot demonstrate as an observation, not a finding.
No, by design. The scope and rules of engagement are agreed in writing before anything begins, testing is scheduled, and anything higher-risk is coordinated with you. Written authorization is required before any active testing starts.
Every finding demonstrated with proof it is real and the fix, ranked by real risk — plus a hardening session where we work through the fixes with you, and a free re-test afterward with a closure letter you can show an insurer or board. The fix is the deliverable, not an upsell.
A website test covers a public site and its forms and logins; a web application test adds authenticated testing across roles, plus access-control and business-logic abuse for apps with accounts or payments; an external surface test covers everything of yours the internet can already reach, including forgotten subdomains and email spoofing. If you are not sure, the scoping call decides it.
If you run a public website or application that handles logins or data, testing has clear value. If you are not yet sure what most needs protecting, a posture review or consulting engagement comes first — you cannot meaningfully test an estate nobody has mapped.