Authorized engagement flow

Permission → short intake → we break it → logs + findings → refund if no Critical.

We need your permission. Domain, founder LinkedIn, one app URL, and threats you already fear are enough. Stack helps but is optional. You get a full authorized test and logs of what we touched.

  1. 01

    Your permission

    Written authorization from someone who can approve testing. That is the hard requirement — we do not touch systems without it.

  2. 02

    Minimal intake

    Domain, a founder LinkedIn, one application URL, and any threats you already worry about. Stack and extra URLs help us go faster — optional, not required.

  3. 03

    We break it on purpose

    Full authorized testing: LLM-assisted offense plus human operators hunting holes across what you authorized.

  4. 04

    Logs + findings

    You receive findings and logs of what we touched so you can see the trail — before a malicious actor leaves one you cannot control.

  5. 05

    Refund if no Critical

    If no Critical lands in scope under the SOW, the package fee is refunded per contract.

Clarity

What this is — and is not

  • — Permission required. No work without it.
  • — Full hunt for holes on what you authorize — with logs of what we touched.
  • — Stack and extra URLs optional; they only make us faster.
  • — Not a warranty that all vulnerabilities will be found.
  • — Binding terms live in the SOW, not in draft marketing.