The basis on which we publish this website and enter advisory engagements.
Content here is general information, not advice for your specific situation. Prices shown are starting points for typical scope and are not offers. Scope, deliverables and fees for any engagement are agreed in writing before work begins.
Our deliverables are recommendations based on the information available to us during the engagement. Decisions about whether to act on them remain yours. Where a question requires legal, regulatory or accounting interpretation, we will say so and recommend qualified counsel.
We perform no intrusive security testing without written authorisation identifying the asset owner, the systems in scope, the permitted techniques and the testing window. A security assessment reduces risk; it cannot certify that a system is free of vulnerabilities.
We treat what you share as confidential and use it only to deliver the engagement. Case studies are published only with permission, and anonymised unless you agree otherwise.