One firm, pointed both ways.
Most agencies build and walk away; most security firms arrive long after the build and hand over a PDF. The two sides never meet. We run both practices, so the work is never handed to a stranger and never defended by whoever was in a hurry to ship it.
Scope of practice
The kind of work
Product and marketing sites, web apps, APIs and the pipelines that ship them — then penetration testing, audits, incident recovery and monitoring on top of what exists.
Every engagement is scoped against your stack, your team and your budget, and written down before anything is touched.
Who we work with
Startups and small teams — the ones larger consultancies quote out of reach. You get the same depth without a six-figure retainer or an account manager in the middle.
You talk to the person who wrote the code or ran the test. When you email after the invoice clears, the same person answers.
How we operate
You cannot attack a system well without knowing how it was assembled, and you cannot assemble one well without knowing how it comes apart. Splitting those two jobs across two vendors is how software ends up shipped and indefensible at once.
- One firm, accountable for both halves
- The build and the assessment answer to the same firm. No handover document, no ramp-up week, and no vendor blaming the other vendor for the finding.
- Fast when it actually counts
- Under four hours on a critical incident. An active breach does not wait for business hours, and neither does the person who answers.
- Nothing to lock you into
- Open tooling, documented configs, plain-language playbooks, and the repository in your own organisation from day one. If you outgrow us, all of it leaves with you.
Principles
Built hard, then attacked
Everything we ship goes through our own offensive practice before it reaches you. Security is a stage of the build, not a service bought afterwards at ten times the cost.
Sized for small teams
Startups and small businesses get the engineering and testing depth large consultancies reserve for enterprise, without the retainer or an account manager in the middle.
Fix it, don't just file it
A finding you have not closed is still a finding. We write the patch, or sit with the engineer who does, then re-run the original exploit to prove it fails.
No buzzword zone
We say what is broken, how someone would use it, and what stops them — in words your engineers and your board both follow, with the request that proves it attached.
Five things we will not do, and why.
Test a system without written authorisation
From someone actually entitled to give it. Scope, out-of-bounds systems, testing windows and an escalation contact go in writing first. If the system is not yours, we need the owner on the thread.
Hand over a scanner export and call it an assessment
A tool run is thirty minutes of work and a plausible-looking PDF. If we cannot show you the request that proves a finding, it does not go in the report.
Hold your code, your configs or your reports
The repository is in your organisation from the first commit and the deliverables are yours on payment. There is no vendor account you have to ask us to open.
Bill a retainer while nothing is being closed
Ongoing cover is monitoring and re-testing that produces something you can read each month. If there is a month where we have nothing to show you, say so and we will pause it.
Put a number on it before we understand it
A quote given before a scoping call is either padded or about to be revised. Thirty minutes first, then a fixed fee in writing.
Who you talk to
The engineer who wrote the code, or the one who ran the test. There is no account manager in the middle, and there is nobody whose job is to relay a question to somebody else and send the answer back a day later.
That is a deliberate limit on how much work we take at once. It also means that when you email after the invoice has cleared, the same person answers.
