Process
How we work
How an engagement runs, what each side provides and which rules apply during the test.
Process
Six phases
Intro call and scoping
Week 030 minutes, non-binding. We clarify what is tested, whether the run is whitebox (with source code access) or blackbox (external view only), which environments exist and what stays out of scope. The result is a written scope with effort and price, or a recommendation for a different setup.
Contract and authorization
before every testFramework agreement, NDA and the test authorization: a document that names the test target, domains and IP ranges, test window, permitted and excluded techniques and an emergency contact. If personal data is processed, a data processing agreement is added. If your system is with a hosting provider, we check together whether their approval is needed.
CVE scan and pentest models
Phase 1 of the testIn a whitebox run the codebase and its dependencies are first scanned for known CVEs. Our penetration-testing models, running on our own hardware, then map the attack surface and test it; in a blackbox run they start from the outside with only the scope. The result is a list of candidates, not yet findings.
Manual verification
Phase 2 of the testAn analyst reproduces every candidate and assesses it in context. Candidates that are not exploitable are discarded and documented. In parallel, analysts test by hand what automation does not cover: permission models, business logic and attack chains.
Report
Wrap-upAn executive summary and a technical section. Findings are classified by CWE, and the report lists the CVEs tested and what else we did. Every finding has evidence, reproduction steps, impact and a recommendation.
Debrief and retest
after the fixWe go through the report with your team. After the fix we retest the affected findings and document the result.
Rules of engagement
Rules during the test
These points are part of every test authorization.
Abort criteria
If production operations are at risk, we stop and escalate to the emergency contact. Availability tests only if explicitly commissioned.
Data minimization
We extract only as much data as is needed as proof. Real personal data is not exported but documented masked.
No disclosure
Findings stay between you and us. Publications, even anonymized, only with your written consent.
Without a signed authorization no test takes place. This includes short preliminary checks and systems that obviously belong to you. Unauthorized access to third-party systems is a criminal offence under sections 202a–c of the German Criminal Code. More under Security and trust.
Background
Why test regularly
A single assessment per year does not cover the releases in between. New endpoints and dependencies can introduce vulnerabilities at any time.
Point in time
One assessment per year does not cover the rest of the year.
Cost per run
Day rates make frequent testing expensive, so testing happens less often than it should.
Scanner noise
Pure tool reports list hundreds of hits without context.
Source code
Many companies are not allowed to send source code to a cloud service.
FAQ
Frequently asked questions
Does our source code leave the building?
It leaves your environment, because you hand it to us. It does not go to cloud AI providers. Source code is analysed in an isolated, offline environment on hardware we operate ourselves.
Is this a real pentest or just a scanner?
Both, in layers. A known-CVE scan of your codebase is the baseline. On top of that our penetration-testing models and analysts test what no CVE list contains: business logic, permission models and attack chains. A person reproduces every finding in the report.
What is the difference between whitebox and blackbox?
In a whitebox run you give us source code access, ideally with architecture notes and a test environment. We scan the codebase for known CVEs, test it with our own models and attack the running application using what the code shows. In a blackbox run we only get the target and the scope and work like an external attacker. We recommend a mode during scoping. The two can be combined.
Do you test systems that are online?
Yes. For blackbox runs against online systems, our test traffic comes from our own infrastructure over the internet and only touches the targets in your signed scope, within the agreed time window.
How many false positives does the report contain?
None. A person reproduces every finding before it goes into the report. On request we list discarded candidates in an appendix.
What do you need from us before you may test?
A signed test authorization with a defined scope, test window and emergency contact, plus a framework agreement and NDA. Without these documents we do not start. If the system is with a hosting provider, we may also need their approval.
Can we use the report for ISO 27001, SOC 2 or NIS2 audits?
The report documents scope, period, testers, findings by CWE, the CVEs tested and the retest. It can serve as evidence of technical testing. We are not a certification body and do not issue certificates.
What does it cost?
Pricing is on request. See Pricing.
Book an intro call
30 minutes, non-binding. We clarify scope, test mode and price.
- No test without written authorization and a defined scope.
- Source code and test data never go to cloud AI providers.
- Every finding is verified by a person before delivery.