- Automated discovery, manually verified
- 6-8 page report and a 45-minute call
- The cheapest way to find out if you have a problem
Priced by scope, not by hours you can't verify.
Every engagement states the assets in scope, the deliverable and the price before it starts. If the scope grows, we re-quote in writing rather than letting the invoice drift. Above $25,000 I stop quoting from a table and we talk — a scope that size deserves a conversation, not a form.
Three ways to buy
- Report in the format your auditor expects
- Dated attestation letter
- Remediation retest included
- Second short pass at 6 months, inside your SOC 2 window
- One scope of your choice
- The areas most pentests leave out
- Same deliverable and same retest
Assessments — fixed price per scope
Every engagement includes one retest within 30 days, at no extra cost, to confirm the fixes landed.
What I don't do
Remediation is executed by the teams that own the asset. What you get from me is the finding, the reproduction, the recommendation and the retest — not a change pushed into your production systems by an outsider.
Saying this out loud is the point. An external tester with write access to your infrastructure is a risk you are adding, not removing.
Same reason I don't sell continuous monitoring: running a platform around the clock is a different business with different economics, and pretending otherwise would mean charging you for a dashboard instead of for judgement. What you buy here is a person looking at your exposure at the moments when it actually changed.
- Continuous 24/7 monitoring — that is a platform, and good cheap ones already exist
- Incident response and forensics
- Executing fixes inside your environment
- Issuing compliance certifications
- Physical intrusion and social engineering
- Reselling anyone else's scanning platform
Not sure which one you need?
Start with the free snapshot. It usually answers the question by itself.