Methodology
Standards a reviewer can check your report against.
We test against established, recognized standards — which is what makes results defensible when a reviewer asks how the assessment was conducted.
| Standard | Applied to |
|---|---|
| OWASP WSTG | Web application testing |
| OWASP MASTG | Mobile application testing |
| OWASP API Security Top 10 | API and backend testing |
| OWASP ASVS | Secure development requirements |
| PTES | Overall engagement structure |
| NIST SP 800-115 | Technical assessment methodology |
| CIS Controls | Infrastructure hardening benchmarks |
| PCI DSS Req. 11.4 | Payment environment testing and segmentation |
Findings are scored using CVSS v3.1, with severity adjusted for real-world exploitability in your environment rather than reported as raw base scores.
How an engagement works
Seven steps from the first call to the clean report you can submit.
-
1
Scoping call
We establish what needs testing, what the report is for, and who will review it. The end requirement shapes the entire engagement.
-
2
Authorization and rules of engagement
Written scope, signed testing authorization, agreed testing windows, emergency contacts. Nothing begins without documented permission.
-
3
Reconnaissance and mapping
We map the full attack surface — often finding exposed services the client didn't know were reachable.
-
4
Testing
Automated coverage for breadth, manual testing for depth. Critical findings are reported immediately rather than held for the final report.
-
5
Reporting
Full documentation within ⟨5⟩ business days, followed by a walkthrough call with your technical team.
-
6
Remediation window
Your team fixes; we support. Direct access to the tester who found each issue.
-
7
Retest and final report
Verification of every fix, and the clean report you can submit.
What you receive
Every assessment delivers a complete evidence package, not a scanner export with a logo on it.
-
Executive summary
Overall risk posture in plain language for the person signing off, with an explicit statement of outstanding findings by severity.
-
Technical findings report
Each finding with CVSS v3.1 score, business impact, affected components, proof-of-concept evidence, and reproduction steps.
-
Remediation plan
Specific, actionable guidance ranked by priority, written for the developers implementing it.
-
Scope and methodology statement
Every tested URL, IP, endpoint, and application build with version numbers; testing dates; standards followed; tools used.
-
Tester credentials and independence statement
Certifications held and a signed declaration of independence. Compliance reviewers check this first.
-
Retest report
Verification that each finding is closed, with a clear final position.
-
Signed and stamped attestation letter
On company letterhead, in the format banks and PSPs expect.
Reports delivered in English and Arabic on request.