Full authorized test
We hunt for every hole we can find in the business systems you authorize — not a light scan for show.
Flat package
Pay us to break it on purpose. Full authorized testing, logs of what we touched, flat price. Binding Critical definition and refund rules appear in the SOW. Mock payment on this site until a provider is chosen.
Included
We hunt for every hole we can find in the business systems you authorize — not a light scan for show.
You get evidence and logs showing what we accessed and what we tried, so you see the work — not just a summary slide.
One price to break it on purpose before a malicious actor does. Start intake on this site; SOW is binding. Mock payment until a provider is chosen.
Full refund when no Critical (as defined) is found in scope — subject to exclusions and the signed contract.
Critical definition
Aligned with ExploitGenie README §5 framing for this draft. Final language is SOW-only.
Confirmed read access to bulk personally identifiable information outside intended authorization.
Ability to execute attacker-controlled code on an in-scope system, including pre-authentication paths.
Account or session compromise that yields durable control of an authenticated identity in scope.
Practical denial-of-service against an in-scope service without credentials, at operationally meaningful scale.
Money-back protections
When the engagement completes under the SOW and no Critical (as defined in that SOW) is found in scope, the package fee is refunded in full — unless an exclusion applies.
Exclusions (draft)
Request engagement
Required: permission, domain, founder LinkedIn, one app URL, threats you worry about. Everything else is optional. Entity formation is in progress.