The studio

One firm, pointed both ways.

Most agencies build and walk away; most security firms arrive long after the build and hand over a PDF. The two sides never meet. We run both practices, so the work is never handed to a stranger and never defended by whoever was in a hurry to ship it.

Scope of practice

The kind of work

Product and marketing sites, web apps, APIs and the pipelines that ship them — then penetration testing, audits, incident recovery and monitoring on top of what exists.

Every engagement is scoped against your stack, your team and your budget, and written down before anything is touched.

Who we work with

Startups and small teams — the ones larger consultancies quote out of reach. You get the same depth without a six-figure retainer or an account manager in the middle.

You talk to the person who wrote the code or ran the test. When you email after the invoice clears, the same person answers.

How we operate

You cannot attack a system well without knowing how it was assembled, and you cannot assemble one well without knowing how it comes apart. Splitting those two jobs across two vendors is how software ends up shipped and indefensible at once.

One firm, accountable for both halves
The build and the assessment answer to the same firm. No handover document, no ramp-up week, and no vendor blaming the other vendor for the finding.
Fast when it actually counts
Under four hours on a critical incident. An active breach does not wait for business hours, and neither does the person who answers.
Nothing to lock you into
Open tooling, documented configs, plain-language playbooks, and the repository in your own organisation from day one. If you outgrow us, all of it leaves with you.

Principles

Built hard, then attacked

Everything we ship goes through our own offensive practice before it reaches you. Security is a stage of the build, not a service bought afterwards at ten times the cost.

Sized for small teams

Startups and small businesses get the engineering and testing depth large consultancies reserve for enterprise, without the retainer or an account manager in the middle.

Fix it, don't just file it

A finding you have not closed is still a finding. We write the patch, or sit with the engineer who does, then re-run the original exploit to prove it fails.

No buzzword zone

We say what is broken, how someone would use it, and what stops them — in words your engineers and your board both follow, with the request that proves it attached.

Where we stop

Five things we will not do, and why.

01

Test a system without written authorisation

From someone actually entitled to give it. Scope, out-of-bounds systems, testing windows and an escalation contact go in writing first. If the system is not yours, we need the owner on the thread.

02

Hand over a scanner export and call it an assessment

A tool run is thirty minutes of work and a plausible-looking PDF. If we cannot show you the request that proves a finding, it does not go in the report.

03

Hold your code, your configs or your reports

The repository is in your organisation from the first commit and the deliverables are yours on payment. There is no vendor account you have to ask us to open.

04

Bill a retainer while nothing is being closed

Ongoing cover is monitoring and re-testing that produces something you can read each month. If there is a month where we have nothing to show you, say so and we will pause it.

05

Put a number on it before we understand it

A quote given before a scoping call is either padded or about to be revised. Thirty minutes first, then a fixed fee in writing.

Who you talk to

The engineer who wrote the code, or the one who ran the test. There is no account manager in the middle, and there is nobody whose job is to relay a question to somebody else and send the answer back a day later.

That is a deliberate limit on how much work we take at once. It also means that when you email after the invoice has cleared, the same person answers.

support@sentrystack.io