root64Offensive Security. Cyber Resilience. Trusted Expertise.
About

About Root64

A small offensive security practice. Every engagement is delivered by the people who scoped it.

Independent by design

Small enough to stay accountable. Experienced enough to go deep.

[COPY REQUIRED: founding story and practice background — approved by business owner.]

[COPY REQUIRED: team size and delivery model — approved by business owner.]

The people who scope the work deliver the work.
Representative offensive security team collaboration
64 Attack paths. One clear answer.
Operating principles

What we hold to

01

Written authorisation before any activity

No test begins on a verbal approval, and no asset is touched that the authorisation does not name.

02

We report what we found

Not what makes the engagement look impressive. A quiet report on a well-built system is a valid result.

03

No security theatre

We do not sell certification against standards that do not certify, and we will not describe anything as unhackable, guaranteed or 100% secure. Nobody can honestly say that.

04

Your data stays yours

Evidence is minimised, access-controlled during the engagement and destroyed on the schedule agreed in the contract.

Methodology

Standards our work is measured against

Published, reviewable methodology—not an internal checklist nobody else can inspect.

01OWASP ASVSApplication security verification baseline
02OWASP WSTG / MASTGWeb and mobile testing methodology
03MITRE ATT&CKAdversary technique mapping for red team work
04NIST SP 800-115Technical testing and assessment methodology
05NIST SP 800-218 SSDFSecure development practices
Your next move

Start a conversation

Contact us