About
Authorized review. Clear answers.
For CEOs, founders, and IT leaders who need a straight answer: what can an outsider reach, and what should we fix first?
We work under written authorization only. Deliverables emphasize business impact and next steps — calm process, no scare tactics.
How an assessment runs
- Confirm ownership, scope, and written authorization (rules of engagement)
- Assess only the agreed surfaces in an isolated engagement setup
- Validate carefully — evidence first, no destructive testing
- Report in business language, then remediation call and bounded retest
Confidentiality and evidence
Client data and evidence stay inside the engagement. We minimize what we collect, protect artifacts during the engagement, and tear down engagement environments when work ends. We do not publish client findings.
Authorization and rules of engagement
No probing without written authorization from someone who can approve testing on the listed domains. Rules of engagement define in-scope hosts, methods, and out-of-bounds activities before paid work starts.
Where we work
We primarily serve European and North African B2B SaaS and digital businesses with production web applications — remote delivery under agreed time zones.
We don’t
- Unauthorized probing — or work on domains you cannot approve
- Destructive testing
- Unpaid deep reconnaissance beyond the Free Brief
See a sample Exposure Brief memo · See services
Engagements: engagements@truehat.com
