00By application · Limited each quarter
See your organisation
the way an adversary does.
One full day of manual reconnaissance against your external attack surface, presented back to you in a private debrief. There is no cost and no obligation — we take on a small number of these each quarter because they are the most honest introduction to how we work.
- External attack surface mapping
- OSINT & credential exposure review
- Human risk profile
- Private debrief call + written summary
//The honest version
Why would we do this for nothing?
Because it is the most efficient sales conversation either of us will ever have. Most organisations genuinely do not know what they are exposing. A day of reconnaissance nearly always surfaces something worth knowing — and you learn more about whether we are any good from one real finding than from any amount of marketing.
If what we find worries you, we can talk about a full engagement. If it does not, you have lost nothing and you keep the report. We would rather earn the work than advertise for it.
No credit card, no trial, no automated drip sequence afterwards.
01What is covered
Three surfaces, one day, entirely by hand.
This is reconnaissance, not exploitation. Nothing is attacked, nothing is disrupted, and no credentials are ever used — the whole exercise is designed to be invisible to your operations team.
External attack surface
Everything of yours that is reachable from the internet — including the assets nobody remembers standing up.
- Domain, subdomain and IP enumeration
- Exposed services and administrative interfaces
- Outdated software and known CVEs
- Certificate and DNS hygiene
OSINT & credential exposure
What an adversary can learn about you before sending a single packet at your infrastructure.
- Corporate credentials in breach corpora
- Secrets committed to public repositories
- Documents and metadata leaking internals
- Supplier and partner relationships
Human risk profile
The people an attacker would target first, and the pretexts your business context makes credible.
- Key personnel and reporting structure
- Email address format and validity
- Public footprint that enables pretexting
- Most plausible initial-access routes
02How it works
From application to debrief in about two weeks.
- 01
Apply
Tell us who you are and what you are responsible for. A short call confirms scope and that you are authorised to request testing.
- 02
Authorise
A mutual NDA and a written authorisation to test. Nothing begins until both are signed — this is non-negotiable.
- 03
Reconnaissance
One full day of manual reconnaissance and OSINT. Passive and non-intrusive throughout; nothing is exploited.
- 04
Debrief
A private walkthrough of what was found, what it means, and what we would fix first — plus a written summary.
03Boundaries
What this is not.
Being straight about the limits is part of the point. A one-day reconnaissance briefing is a strong indicator of exposure — it is not a penetration test and should never be presented to an auditor as one.
You do get
- A real picture of your external exposure
- Findings ranked by exploitability
- A live debrief with the person who did the work
- A written summary you own outright
You do not get
- Exploitation or proof-of-concept attacks
- Internal network or authenticated testing
- A compliance-grade attestation letter
- Coverage of every asset you own
One per organisation. Requests are accepted from someone authorised to commission security testing for the domain in question — a written authorisation is required before any work starts. This protects both of us.