Methodology
The full engagement lifecycle, our testing principles, how severity is rated, what a report contains, and what an assessment cannot tell you.
Material that helps you evaluate security testing before you buy it, and helps your team act on it afterwards.
Everything below is published and specific. It is deliberately the material a security reviewer or an engineering lead would want before commissioning work.
The full engagement lifecycle, our testing principles, how severity is rated, what a report contains, and what an assessment cannot tell you.
A worked example of a single finding, written out in full: severity reasoning, reproduction steps, evidence, business impact, remediation, and retest result.
How authorization works, what must be agreed before testing begins, what is excluded by default, and how to report a security issue to us.
How a success-based engagement is defined, how the objective and success criteria are agreed, and where the boundaries sit.
We are setting up a dedicated publication for longer technical writing, research notes, and analysis. It is not live yet, and we would rather say so than point you at a link that does not work.
When it launches, it will be a separate publication with its own subscription, so the marketing site and the writing stay independent of one another. Until then, the material on this page is the substantive reading available.
What we intend to publish
Writing that is specific enough to be useful, on the problems we actually encounter:
These are planned topics, not published articles. Nothing here is presented as an existing publication record.
Web, API, access control, and cloud configuration testing for a SaaS product.
Ongoing review of new features, fixes, and infrastructure changes.
Security testing for LLM features, agents, RAG pipelines, and tool access.
Ask it directly. If it is a good question, it will probably become one of the first things we publish.