FAQ

Frequently asked questions

Common questions about how our penetration testing works. If yours isn’t here, get in touch.

Questions and answers

How long does a penetration test take?

It depends entirely on scope and what we find. A single website or URL is often a few hours. A black-box engagement where we discover many pivotable assets can run for days. There is no fixed period — the findings drive how deep the test goes, and we scope each engagement to what it actually needs.

Will testing disrupt our systems?

No. We don’t use denial-of-service, lockout or destructive techniques, and we stop each proof-of-concept at the smallest evidence needed to demonstrate impact. Out-of-scope systems we discover are logged, not tested.

Does our data go to a commercial AI provider?

No. Our AI models run entirely on our own local hardware. Nothing about your systems — code, findings, credentials or traffic — is sent to a commercial AI provider or a frontline model.

What’s in the report?

An executive summary, then every finding with a CVSS 3.1 severity rating, business impact, reproduction steps, and both a short-term mitigation and a long-term fix. Each finding is mapped to the relevant ISO/IEC 27001:2022 control, and the report includes a remediation tracking matrix and an evidence appendix.

Do you retest after we fix things?

Yes. The report tracks remediation per finding, and we retest to verify your fixes and update each finding’s verification status — which is also the closing evidence for an ISO 27001 audit.

What do you need to get started?

The systems in scope, authorisation to test them, and any timing or compliance requirements. For internal or cloud scope we’ll agree what access you provide. We propose a scope from there.

Is the report suitable for ISO 27001?

Yes. Findings are mapped to Annex A controls and the format is built as audit evidence. See our ISO 27001 penetration testing page.

Where are your clients based?

Worldwide. Testing is remote — against internet-reachable systems, or through access you provide for internal and cloud scope — so location isn’t a constraint.

How do we get a quote?

Email [email protected] or book a scoping call. Tell us what needs testing and we’ll come back with a proposed scope.

Still have a question?

Email us and we’ll answer it — and scope a test if you’re ready.