About

Authorized review. Clear answers.

For CEOs, founders, and IT leaders who need a straight answer: what can an outsider reach, and what should we fix first?

We work under written authorization only. Deliverables emphasize business impact and next steps — calm process, no scare tactics.

How an assessment runs

  1. Confirm ownership, scope, and written authorization (rules of engagement)
  2. Assess only the agreed surfaces in an isolated engagement setup
  3. Validate carefully — evidence first, no destructive testing
  4. Report in business language, then remediation call and bounded retest

Confidentiality and evidence

Client data and evidence stay inside the engagement. We minimize what we collect, protect artifacts during the engagement, and tear down engagement environments when work ends. We do not publish client findings.

Authorization and rules of engagement

No probing without written authorization from someone who can approve testing on the listed domains. Rules of engagement define in-scope hosts, methods, and out-of-bounds activities before paid work starts.

Where we work

We primarily serve European and North African B2B SaaS and digital businesses with production web applications — remote delivery under agreed time zones.

We don’t

  • Unauthorized probing — or work on domains you cannot approve
  • Destructive testing
  • Unpaid deep reconnaissance beyond the Free Brief

Engagements: engagements@truehat.com