scoped · expert-run · validated

Offensive testing,
with the paperwork sorted

A real penetration test that behaves like an attacker — bounded by a signed authorisation, accelerated by an AI operator, and run and monitored throughout by our own security testers. The findings land as evidence in your ISO/IEC 27001 control register rather than in a PDF nobody opens twice.

how it tests

An operator, not a checklist

A fixed scanner runs the same list every time. Our AI operator reasons about what it finds and decides what to look at next — with one of our testers scoping the work, watching it run and deciding what matters.

  • Scoped by a human before anything starts
  • Adaptive probing that follows the evidence
  • Each finding validated before it reaches your report
  • Full transcript, reviewed by the tester who ran it

Inside the engine →

how it stays safe

Nothing runs unauthorised

Safety is built into the engine, not bolted on. The scope you agree is enforced in code, and anything active waits for a person to approve it.

  • Signed authorisation and allowed-host scope required first
  • Passive by default — probes and lookups only
  • Approval gate on every active action, deny-by-default
  • Time-boxed to a window you agree

All seven guardrails →

how a test runs

From first scope to signed report

01

Scope & authorise

We agree the hosts, the window and the rules of engagement, and you sign a short authorisation and indemnity. Nothing runs before that signature is on record.

02

Validate

The AI operator works through your surface, reasoning about what it finds and confirming each issue instead of dumping a raw scanner list. Anything active pauses for your approval.

03

Evidence

Every confirmed finding is written up with proof and severity, then mapped to the ISO/IEC 27001 control it breaks — so it lands as audit evidence, not just a ticket.

04

Report & re-scan

You get a signed report, reviewed by a person before it reaches you. Fix what matters, then we re-scan to confirm the issues are actually closed.

automation with a name on it

Automated, never unattended

The tooling is what makes a test fast and thorough. It isn't what makes it trustworthy. Every engagement is owned end to end by a qualified security tester who scopes it, watches it run, and puts their name on what comes out.

A tester scopes it

Targets, exclusions, the window and the rules of engagement are agreed by a person who understands your environment — not inferred from a domain you typed into a box.

before

Watched while it runs

The run is monitored live. If something looks fragile, behaves unexpectedly or starts touching what it shouldn't, a human stops it — and anything intrusive waits for explicit approval before it goes near production.

during

Triaged by hand

Machine-confirmed isn't the same as worth your time. Our testers cut the noise, correct the severity, and add the business context that turns a finding into a decision.

after

Signed by a person

No report reaches you unreviewed. A tester reads it, stands behind it, and is the one you talk to when you want to argue about a rating.

accountable

Why we're explicit about this. "AI-powered" has come to mean "nobody was home". Automation covers more ground in a day than a person can, and it never gets bored on the eightieth host — but judgement, restraint and accountability aren't things you can schedule. So we do both, and we tell you which is which.

deliverables

Documents, not just a data dump

What you're left with after a test should stand up in a boardroom and in front of an auditor — not expire the moment the tester moves on.

  • Scope of Work with objectives, exclusions and rules of engagement
  • Authorisation and indemnity, signed before testing begins
  • Findings report — severity, proof and remediation per issue
  • Every finding mapped to the ISO 27001 control it breaks
  • A re-scan to confirm the fixes landed
  • An executive summary your board can read without a translator
  • A named tester you can call about any of it

Request a scope

findings reportseverity
PT-011Privileged session without MFAhigh
PT-014Missing Strict-Transport-Securitymedium
PT-015Cookie without Secure attributelow
PT-018Verbose error disclosurelow
Mapped to Annex AA.5.17 · A.8.9 · A.8.23
the difference

Why the findings don't go stale

A standalone pen test gives you a snapshot. Because ours writes into the same control register your ISMS runs on, the fix is tracked, the evidence is kept, and next year's auditor can see both.

Findings become evidence

Each validated issue lands against the Annex A control it breaks, with proof attached and a SHA-256 integrity hash on the artefact.

closed loop

A clean pass counts too

Where the test finds nothing, that result is recorded as evidence toward the control rather than quietly discarded.

positive proof

Remediation is tracked

Findings carry an owner, a root cause and a corrective action through to closure — the clause 10 machinery, not a spreadsheet.

clause 10

It shows on your Trust Center

"Last penetration test: July 2026" is a line your prospects can see for themselves, published from real state.

public proof

Let's scope your first test

Tell us what's in scope and we'll come back with a plan and a quote.