Methodology

Security work starts with authority and ends with verification.

The exact technical methodology varies by target. The control process does not.

01

Qualify

Understand the application, assessment driver, environment, and whether the requested work belongs within our specialization.

02

Scope

Identify targets, accounts, roles, tenants, exclusions, testing windows, sensitive data, stop conditions, and communication paths.

03

Authorize

Complete Rules of Engagement and written authorization. No intrusive testing begins before this gate.

04

Model

Map assets, identities, roles, objects, actions, tenant boundaries, data flows, and AI/tool trust boundaries relevant to the scope.

05

Test

Use manual analysis and appropriate tooling to challenge the agreed controls while staying inside the authorized scope.

06

Validate

Reproduce potential findings, eliminate false positives, establish impact, and preserve the evidence required for remediation.

07

Report

Deliver clear findings with affected surface, exploitation path, impact, evidence, root cause, and remediation direction.

08

Retest

After remediation, verify whether the original path is closed and identify material regressions within the agreed retest scope.