A testing firm that ships its work while it is still useful.
What we do
Manual penetration testing, delivered as it happens
We test web applications, APIs, mobile applications, networks and cloud environments, plus the assurance work that sits alongside them: secure code review, phishing simulation and compliance readiness. Every engagement is fixed-price, quoted after a scoping call, and typically runs five to ten working days from kickoff to final report.
What arrives is not a document at the end. Findings appear in your workspace as testers confirm them, each with its severity, the affected endpoints, the proof that demonstrates the issue, and guidance on the fix. Your engineers start on the critical items in the first couple of days rather than in the week after the engagement closes.
When something is fixed, you mark it and request a retest from the same screen. A tester verifies it by hand and records whether it passed or failed. That retest is part of the engagement, not a second purchase order.
How we think
Three positions, and what each one costs us
These are the reasons an engagement here is shaped the way it is. Each has a consequence we live with rather than a slogan we repeat.
A finding is only worth writing if it has been proven
A scanner reports what might be true. A tester establishes what is true, then shows the request and the response that make it true. Everything published to your workspace has been reached by hand and demonstrated, so nobody on your side spends a day proving a false positive.
The price should be known before the work starts
Engagements are priced on scope rather than on hours, fixed before work starts, and quoted after a 30-minute scoping call. If more attack surface turns up partway through we tell you what we found rather than raising an invoice for it.
A report nobody can act on is not a deliverable
Findings carry the severity, the affected endpoints, reproduction steps and fix guidance written for the framework you are using. If your engineer cannot reproduce a finding from what we wrote, the finding was not finished.
Why we built Vexil
The delivery format was the part we could not fix by testing better
Four things a document at the end of an engagement cannot do, each included rather than licensed separately.
Instead of
A report at the end of six weeks
Findings publish to your workspace as they are confirmed, so remediation starts on day two rather than after the engagement closes.
Instead of
Retesting means buying another engagement
Mark a finding fixed and request a retest in place. A tester verifies it by hand and records the outcome, and it is included rather than billed as new work.
Instead of
Sharing findings means emailing a PDF
Access is scoped to a project, or narrowed to a single application, so a contractor can work on one thing without receiving the whole estate.
Instead of
The auditor wants it in their framework
The same engagement exports as a technical report, an executive summary, or mapped to PCI DSS, SOC 2, ISO 27001 or HIPAA requirement areas.
See what the platform does in more detail, including how access is scoped and what reporting covers.
Who does the testing
People, and you will know which.
The people who test your systems have come from Big Four cyber practices, enterprise telecom and finance, and are credited with 10+ published CVEs.
Certifications say who is doing the work. What the work is run against - OWASP WSTG, ASVS, the API Top 10, PTES and OSSTMM - is set out with versions on how we test.
Testing
- OSCP
- CRTO
- CPTS
- CPENT
- LPT
- CRTP
- eCPPT
- eJPT
- CAPT
- CIPT
- ASCP
- TryHackMe PT1
Audit and governance
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- CISA
These are certifications held by individuals, not company accreditations. We name the tester on your engagement before it starts, and you can talk to them during it.
Where we are
Remote by design
Testing is remote and scheduled around agreed windows, so the location that matters is where your systems run rather than where we sit. Every engagement is governed by a written rules-of-engagement document covering scope, exclusions, testing hours, permitted techniques and escalation contacts, agreed before anything is touched.
If you would rather ask a question than book a call, [email protected] reaches us and we reply within one working day.
About FAQ
What people ask about us
Is the testing done by people or by tools?
By people. Testers work through the methodology by hand, chaining multi-step issues and abusing business logic, which is where the findings that matter live. Tooling is used for coverage during reconnaissance and its output is kept separate from the findings a tester wrote, so you always know which is which.
What certifications does the team hold?
Between them the testing team holds OSCP, CRTO, CPTS, CPENT, LPT, CRTP, eCPPT, eJPT, CAPT, CIPT, ASCP and TryHackMe PT1 - all penetration testing and offensive security qualifications. On the assurance side the team holds ISO 27001 Lead Auditor, ISO 27001 Lead Implementer and CISA. Engagements are run against OWASP WSTG v4.2, OWASP ASVS, the OWASP API Security Top 10, PTES and OSSTMM.
Where are you based, and where do you work?
Testing is remote, so where your systems are hosted matters more than where we are. Engagements are governed by a written rules-of-engagement document agreed before any testing begins.
Why does a testing firm build its own platform?
Because the delivery format was the part of the industry we could not fix with better testing. A PDF at the end of an engagement cannot show you a critical issue on day two, cannot record a retest, and cannot be scoped to one contractor. Vexil exists so the work reaches you while it is still useful.
Do we have to use the platform?
The findings live there, and reports export to Word, PDF and Excel so anything you need to send onward leaves as a document. Vexil is included with every engagement rather than licensed separately.
Judge the work, not the pitch.
The fastest way to see how deep the work goes is to read one finding with every field it carries, and that is on this site in full.