Nine test types, and who each one simulates
Most clients combine two or three rather than buying all of them. Durations assume a mid-sized environment and are confirmed at scoping.
What the report contains
An executive summary that a non-technical reader can act on, then per-finding detail: how it was reached, what it exposed, how to reproduce it, evidence, and the specific change that fixes it. Ranked by business impact rather than by scanner severity.
What it does not contain
Raw scanner output presented as findings. Severity ratings copied from a database without reference to your environment. A hundred low-risk observations padding out a thin engagement.
Where testing usually leads
Vulnerability management
An annual test is a snapshot. Exposure needs a running process between them.
Red teaming
Once the perimeter holds, test whether your team would notice somebody patient.
Secure code review
For applications you build yourselves, the cheapest place to find a flaw is in the code.
