Most tests end with a PDF and an invoice. Ours ends when the findings are closed. We test your website, your web application and your external surface with your written authorisation, demonstrate every real finding, then sit with you — or your developer — and harden it. Then we test it again, free, to prove it is actually fixed.
Authorised testing only · Fixed scope, fixed price · Re-test included · Call or text (940) 281-6672
Anyone can run a scanner and hand you two hundred results. The work that matters is proving which ones a real attacker could actually use, ranking them by what they would cost you, and then closing them. A finding we cannot demonstrate does not go in the report as a finding — it goes in as an observation, clearly marked.
And a control nobody has tested is not a control. We check whether the thing works, not whether it is documented — the backup that has never been restored, the alert channel nobody has ever received a message on, the login page that rate-limits in theory.
.env and .git directoriesNot sure which fits? That is what the scoping call is for. Prices are starting points — the scope drives the number, and you get it in writing before anything begins.
We test only with your written authorisation, only the assets you name, and only in the window you agree. If your site is hosted by a third party we get their sign-off too, because testing someone else's infrastructure without it is a crime rather than a service.
We do not test destructively. No denial-of-service, no data destruction, no social engineering of your staff unless you specifically ask for it and scope it separately. If we find something critical mid-test we stop and phone you the same hour rather than saving it for the report.
Findings are yours. We hold no copy beyond the engagement plus the re-test window, and we certify deletion in writing when it closes.
A short call to understand what you have and what you are worried about. You get a written scope and a fixed price before anything is touched — and an honest answer if a test is not what you need yet.
Request a scope & quoteOr call the Security Architect directly — (940) 281-6672