Skip to main content

How we work

How we price and work

We do not publish prices, because cost follows scope. Here is what drives the scope, how long engagements typically take, and what we commit to at each step.

What drives scope and cost

Every quote is written against a scope. These are the things that move it.

Assets in scope
How many hosts, IP ranges, applications, API endpoints or AWS accounts are in play. For applications, the number of user roles matters more than the number of pages, because every role boundary has to be tested from both sides.
Environments
Whether we test production, staging, or both, and how closely they match. One environment that genuinely mirrors production is cheaper and more useful than two that differ in ways nobody has written down.
Type of test
External and internal network testing, web application, API, AWS cloud, compliance-driven testing and red team operations each take a different amount of work for the same number of assets. A red team operation is measured in weeks because it tests detection, not just exposure.
Access and starting position
Testing from an authenticated account, a standard user on the internal network, or a read-only cloud role reaches further in the same time than testing from nothing. What we start with is agreed in the scope.
Retesting
Testing engagements (penetration, web application, API, AWS and compliance-driven testing, and red team operations where applicable) include one retest of the reported findings within 90 days of the report. Further rounds are quoted separately. So is a retest after major changes to the system, which is scoped before it starts.

Typical durations

Testing time for a typical scope, not a quote. Your written quote states the actual duration for your environment, and reporting follows the testing window.

Typical testing time by type of engagement
External penetration testTypical: 3 to 5 daysScales with the number of internet-facing hosts and services.
Internal network and Active DirectoryTypical: 5 to 10 daysScales with the number of domains, sites and network segments.
Web applicationTypical: 5 to 10 daysScales with user roles and multi-step workflows more than with page count.
APITypical: 3 to 10 daysScales with endpoints and roles, and with whether GraphQL is in use.
AWS cloudTypical: 5 to 10 daysScales with the number of accounts and how identity is shared between them.
Compliance-driven penetration testTypical: 1 to 3 weeksSet by what your framework and your assessor put in scope.
Red team operationTypical: 4 to 8 weeksMeasured against objectives rather than assets.
RetestTypical: 1 to 2 daysIncluded once, within 90 days of the report.

How an engagement runs

  1. Scoping

    A short call, or the scoping questionnaire below if you would rather write it down. We want to know what matters most, what is in scope, and any deadline you are working to, such as an audit date.

  2. Written quote

    Within 2 business days

    A written scope and quote, stating what will be tested, from what starting position, over how long, and what you will receive.

  3. Authorisation

    Rules of engagement and written authorisation to test, signed before anything starts, with a named contact on each side who can pause the work.

  4. Testing

    The agreed window. Anything serious is raised as soon as it is confirmed rather than held back for the report.

  5. Report

    A technical report with reproduction steps for every finding, and a separate summary for people who will not read the technical detail.

  6. Retest

    Included once, within 90 days

    Once you have fixed the findings, we test the fixes and record the result, so you have evidence that each one is closed.

We respond to every enquiry within one business day. For an active incident, call +1 (618) 203-0104.

Scoping questionnaire

Answer what you can, in any order, and send it through the contact form. Rough numbers are fine. We will come back with any questions and then a written quote within 2 business days.

  1. What do you want tested: networks, web applications, APIs, AWS accounts, or people and process?
  2. Roughly how large is it: hosts or IP ranges, applications and their user roles, API endpoints, AWS accounts?
  3. Is testing against production, staging, or both, and how closely do they match?
  4. Is this driven by a framework or a customer, such as SOC 2, PCI DSS, ISO 27001, HIPAA or a security questionnaire, and is there an audit or deadline date?
  5. Has it been tested before, and can you share the previous report?
  6. Are there systems, times or techniques that must be excluded?
  7. Who is the technical contact during testing, and who needs to see the report?