FAQ

Answers before you ask.

Common questions about how an engagement actually runs, from scoping to the final report.

How long does a typical engagement take?
Most penetration tests run 1–3 weeks depending on scope; red team engagements typically run 4–8 weeks. Scoping is usually agreed within a business day.
Will testing disrupt our production systems?
No. Rules of engagement are agreed up front, including blackout windows and any systems that are off-limits for exploitation. Denial-of-service techniques are never used without explicit written sign-off.
Do you provide retesting after remediation?
Yes. Every engagement includes one round of retesting for confirmed findings once fixes are deployed, at no extra cost.
What does the final report include?
An executive summary for leadership, a prioritised findings list scored by business impact, and a technical appendix with reproduction steps for your engineering team.
Can testing be mapped to a compliance framework?
Yes — engagements can be scoped and reported against PCI DSS, HIPAA, ISO 27001 or SOC 2 requirements ahead of your audit.
How much does an engagement cost?
Pricing depends on scope — number of assets, complexity, and which service(s) you need. Tell us what you're protecting on the contact form and we'll send a scoped quote, usually the same business day.
Do you sign NDAs before scoping calls?
Yes, we're happy to sign an NDA before any detailed discussion of your environment — just mention it when you reach out.

Still have a question?

We reply to every message the same business day.

Contact Us →