Approach
Authorised, scoped, explained and verified after the fix
An assessment is only useful if it is safe to run and possible to act on. This is how every tr3labs engagement works, from first contact to retest.
- 01
Scope
Every engagement starts with a scoping conversation and ends that conversation with a written agreement: which systems and environments are in scope, which are explicitly out, what test accounts and data we will use, and the testing window.
Testing begins only after we hold written authorisation from someone entitled to give it. If a third party hosts or operates part of the target, we confirm their rules of engagement first.
- 02
Assess
Testing is manual and methodical, guided by how the system is actually used and what an attacker would actually want from it. Tooling supports the work; it does not replace it.
We agree a communication channel up front. If we find something urgent, such as an exposed credential or an actively exploitable flaw on a production system, we tell you immediately rather than saving it for the report. We avoid destructive tests and anything that risks availability unless explicitly agreed.
- 03
Explain
You receive a written report and a walkthrough call. The executive summary is written for people who were not in the room; each finding carries evidence, reproduction steps, business impact and a concrete fix.
We are developers too, so every fix is explained developer-to-developer: concrete changes your team can apply, and we can pair with your engineers on them when that helps. Severity reflects risk in your context, not just a formula, and we stay available for follow-up questions throughout remediation.
- 04
Retest
When your team has remediated, we retest the affected findings and issue an updated report stating clearly what is resolved, what is partially resolved and what remains open.
Where a retest is part of the agreed scope there is no extra charge for it.
What we will not do
- Test anything without written authorisation.
- Ask for your users' passwords, production secrets or confidential data to get started.
- Pad reports with scanner noise or inflate severities to look busy.
- Promise “unhackable”. No honest assessor can.
Ready to scope?
Tell us what you need tested, the rough size of the system and your timeline. We reply with a proposed scope and fixed price.
Request an assessment