VA
Vulnerability AssessmentWhich weaknesses should we prioritize?
Assess vulnerabilities and configuration across agreed assets, triage findings and prioritize risk.
A baseline and recurring assessmentTriaged findings + remediation priorities
EXPERT-LED OFFENSIVE SECURITY
VA / Pentest & Red Team
Expert-led testing from an attacker’s perspective, grounded in your systems and business context. AI helps connect the evidence; your team gets findings it can act on.
Testing starts only with written system-owner authorization and agreed Rules of Engagement.
Conceptual flow: authorize → test → validate → remediate. This page does not test live systems.
THE RIGHT QUESTION, THE RIGHT TEST
Each service answers a different question. Match breadth, depth and objectives to your team’s needs.
Assess vulnerabilities and configuration across agreed assets, triage findings and prioritize risk.
A baseline and recurring assessmentTriaged findings + remediation priorities
Experts validate findings and connected paths, testing business logic and access within authorized scope.
Critical systems, launches and major changesImpact evidence + fixes + agreed retest scope
Simulate an agreed business objective under the ROE to assess prevention, visibility and coordinated response.
Teams ready to exercise defenses togetherAttack narrative + evidence + detection gaps + debrief
KNOWLEDGE CHANGES THE PERSPECTIVE
Both require authorization. The difference is the information and access given to testers, not a guaranteed security level.
OUTSIDE-IN
The tester knows the authorized targets and boundaries, but receives no test account or internal details. Testing begins with what an external user can see and follows discovered paths within the ROE.
PARTIAL KNOWLEDGE
Testers receive accounts and limited context, such as roles or API documentation, to examine cross-user access and business logic. This does not imply access to all source code or internal information.
One example: a customer portal.
Black Box examines pre-login surfaces.
Gray Box adds accounts A / B to test separation.
Scope & ROE → starting context → attacker → test surface → validation → evidence
Select a step below the diagram to pause on it. Explanatory text stays in place during playback.
A GOAL. AN AUTHORIZED PATH. A SHARED LESSON.
Agree a scenario, then use evidence to explain which paths were prevented, what was visible and how the team responded.
Identity / Role — Check whether an agreed test account can reach unintended privileges within authorized roles and systems.
Network Segmentation — Check whether an authorized test host can reach test targets across zones, documenting reachable and blocked paths.
Dashed path to the Blue Team = potential signals to review. Alerts and objective success are not guaranteed.
Not included by default: social engineering, physical security, DoS and third-party testing require separate risk assessment and authorization.
SCOPE AROUND YOUR SYSTEMS
Agree assets, test environments and depth together. Not every engagement includes every area.
Review authentication, authorization, sessions and business logic using agreed test accounts and data.
Customer Portal · API · AdminAssess exposed services, configuration and network boundaries within authorized IP ranges and testing windows.
External / Internal NetworkExamine roles, permissions and trust relationships in agreed environments, subject to cloud-provider policies.
IAM · Cloud configuration · AccessHUMAN JUDGMENT. AI-ASSISTED DEPTH.
Good testing depends on relevant hypotheses, careful impact validation and remediation guidance your team can use. Tools support that work; they do not make the final judgment.
Group findings, connect authorized evidence, suggest follow-up questions and draft reports to reduce repetitive information handling.
Experts choose test methods, check false positives, validate evidence and impact, and prioritize remediation in your organizational context.
Traceable risk reasoning and recommendations tied to your systems, with the context that raw tool output lacks.
AI inputs are limited by scope and data-handling agreements. Masking, retention and permitted tools are defined before work begins, with expert oversight throughout.
CONTROL BEFORE ACTION
Rules of Engagement establish who may test what, using which methods, when testing is allowed and when it must stop.
Confirm written owner authorization, assets, IPs, domains, exclusions and third-party permissions before testing.
Agree windows and permitted methods. If disruption or an out-of-bounds condition occurs, stop and escalate through the agreed contact.
Use test data where possible, collect only necessary evidence, mask sensitive details and agree transfer, retention and deletion.
Review removal of test accounts, files and temporary access as agreed, then confirm outstanding actions and owners.
EVIDENCE THAT LEADS TO ACTION
Explain risk through observed impact, prerequisites, evidence and testing limits so teams can make decisions and track the work.
FROM FIRST CONVERSATION TO RETEST
Identify critical systems, recent changes and what you need to prove.
Confirm scope, ROE, contacts, cost and deliverables.
Execute the plan and escalate material findings through agreed channels.
Review results with system owners and track remediation.
Recheck fixes within the scope and window defined in the proposal.
BEFORE WE BEGIN
Your proposal defines assets, methods, schedule, reports and retesting for your engagement.
Consider VA for an initial risk backlog, pentesting for deeper impact validation and Red Team for objective-led exercises with teams ready to assess defenses together. We can help choose based on your systems and questions.
Targets, boundaries, excluded systems and the ROE must still be clear. The withheld information is internal context or accounts, as agreed. Black Box is not permission to test anything.
Suitability must be assessed first, with defined windows, restrictions, stop procedures and contacts. Some activities may use staging. The system owner must agree acceptable risk.
AI use is governed by experts, scope and data-handling agreements. Permitted tools and inputs are established before work begins. AI does not authorize testing or independently expand scope.
Results reflect the tested scope, time and conditions. They do not guarantee discovery of every weakness or complete protection. Remediate, retest and reassess when systems change.
They depend on asset count, complexity, accounts and roles, Black Box / Gray Box methods or Red Team objectives. Pricing, schedule and retest quantity or scope are specified in the proposal before work begins.
LET’S DEFINE THE RIGHT TEST
Bring your system types, asset count, relevant roles, objectives and preferred window. We will help define the scope and approach.
The references below inform planning, testing and reporting concepts. Actual service scope follows your proposal and ROE.