How we work
How we price and work
We do not publish prices, because cost follows scope. Here is what drives the scope, how long engagements typically take, and what we commit to at each step.
What drives scope and cost
Every quote is written against a scope. These are the things that move it.
- Assets in scope
- How many hosts, IP ranges, applications, API endpoints or AWS accounts are in play. For applications, the number of user roles matters more than the number of pages, because every role boundary has to be tested from both sides.
- Environments
- Whether we test production, staging, or both, and how closely they match. One environment that genuinely mirrors production is cheaper and more useful than two that differ in ways nobody has written down.
- Type of test
- External and internal network testing, web application, API, AWS cloud, compliance-driven testing and red team operations each take a different amount of work for the same number of assets. A red team operation is measured in weeks because it tests detection, not just exposure.
- Access and starting position
- Testing from an authenticated account, a standard user on the internal network, or a read-only cloud role reaches further in the same time than testing from nothing. What we start with is agreed in the scope.
- Retesting
- Testing engagements (penetration, web application, API, AWS and compliance-driven testing, and red team operations where applicable) include one retest of the reported findings within 90 days of the report. Further rounds are quoted separately. So is a retest after major changes to the system, which is scoped before it starts.
Typical durations
Testing time for a typical scope, not a quote. Your written quote states the actual duration for your environment, and reporting follows the testing window.
| Engagement | Typical testing time | What moves it |
|---|---|---|
| External penetration test | Typical: 3 to 5 days | Scales with the number of internet-facing hosts and services. |
| Internal network and Active Directory | Typical: 5 to 10 days | Scales with the number of domains, sites and network segments. |
| Web application | Typical: 5 to 10 days | Scales with user roles and multi-step workflows more than with page count. |
| API | Typical: 3 to 10 days | Scales with endpoints and roles, and with whether GraphQL is in use. |
| AWS cloud | Typical: 5 to 10 days | Scales with the number of accounts and how identity is shared between them. |
| Compliance-driven penetration test | Typical: 1 to 3 weeks | Set by what your framework and your assessor put in scope. |
| Red team operation | Typical: 4 to 8 weeks | Measured against objectives rather than assets. |
| Retest | Typical: 1 to 2 days | Included once, within 90 days of the report. |
How an engagement runs
Scoping
A short call, or the scoping questionnaire below if you would rather write it down. We want to know what matters most, what is in scope, and any deadline you are working to, such as an audit date.
Written quote
Within 2 business days
A written scope and quote, stating what will be tested, from what starting position, over how long, and what you will receive.
Authorisation
Rules of engagement and written authorisation to test, signed before anything starts, with a named contact on each side who can pause the work.
Testing
The agreed window. Anything serious is raised as soon as it is confirmed rather than held back for the report.
Report
A technical report with reproduction steps for every finding, and a separate summary for people who will not read the technical detail.
Retest
Included once, within 90 days
Once you have fixed the findings, we test the fixes and record the result, so you have evidence that each one is closed.
We respond to every enquiry within one business day. For an active incident, call +1 (618) 203-0104.
Scoping questionnaire
Answer what you can, in any order, and send it through the contact form. Rough numbers are fine. We will come back with any questions and then a written quote within 2 business days.
- What do you want tested: networks, web applications, APIs, AWS accounts, or people and process?
- Roughly how large is it: hosts or IP ranges, applications and their user roles, API endpoints, AWS accounts?
- Is testing against production, staging, or both, and how closely do they match?
- Is this driven by a framework or a customer, such as SOC 2, PCI DSS, ISO 27001, HIPAA or a security questionnaire, and is there an audit or deadline date?
- Has it been tested before, and can you share the previous report?
- Are there systems, times or techniques that must be excluded?
- Who is the technical contact during testing, and who needs to see the report?