Written authorisation before any activity
No test begins on a verbal approval, and no asset is touched that the authorisation does not name.
A small offensive security practice. Every engagement is delivered by the people who scoped it.
[COPY REQUIRED: founding story and practice background — approved by business owner.]
[COPY REQUIRED: team size and delivery model — approved by business owner.]
No test begins on a verbal approval, and no asset is touched that the authorisation does not name.
Not what makes the engagement look impressive. A quiet report on a well-built system is a valid result.
We do not sell certification against standards that do not certify, and we will not describe anything as unhackable, guaranteed or 100% secure. Nobody can honestly say that.
Evidence is minimised, access-controlled during the engagement and destroyed on the schedule agreed in the contract.
Published, reviewable methodology—not an internal checklist nobody else can inspect.