Let us scope it properly.

Tell us what is broken, what you are building, or what you are worried about. You will get a reply from an engineer, usually within one business day.

Send us the brief

Rough notes are fine. We would rather read three honest paragraphs than a polished requirements document.

What you send stays between us. We sign an NDA before any technical detail changes hands, and we never run a security test without written authorisation.

HoursMon-Fri, 09:00 to 18:00
ReplyWithin 1 business day

Dealing with an active incident?

Write INCIDENT at the start of your email subject and include a phone number. Those go to the top of the queue. Do not include passwords, keys or log dumps in the first message.

A good first message covers

  • What the system does and roughly how many people use it
  • What is going wrong, and when it started
  • Any deadline or budget range you are working to

Questions we get before the first call.

Do you work with small companies, or only enterprise?
Both. A ten-person company with one critical application often has more at stake, per person, than a large one with a full IT department. What matters is that there is a real problem and someone empowered to make decisions about it.
How do you price work?
Fixed price for defined projects, a monthly rate for retainers, and an hourly rate for advisory work. You get the number in writing before anything starts, and we do not invoice for scope we did not agree with you first.
Can you test a system you did not build?
Yes. That is most of our security work. We need written authorisation from someone who owns the system, and on hosted platforms sometimes from the provider as well. We will not test anything without that, no matter how urgent it is.
What happens to the findings from a security assessment?
They go to you, encrypted, and to nobody else. We keep a copy only for as long as the engagement requires and delete it on request. We never publish client findings, and we never use the name of a client as a reference without written permission.
We already have an IT provider. Is that a problem?
No, and we do not require you to replace them. A good deal of our work is a second opinion, an independent audit, or filling a specific gap alongside an existing provider. We will tell you plainly if we think the incumbent is doing a good job.
Do you take over an unfinished project from another team?
Yes, with one condition: we start with a short paid assessment before quoting the rest. Committing to a fixed price on code we have not read would be guessing, and guessing is how rescue projects go wrong a second time.
Who owns the code and the documentation?
You do, on delivery. Source, infrastructure configuration, diagrams and credentials are yours, held in your repositories and your vault, not ours.