For managed service providers, IT firms and software agencies
Penetration testing for your clients, under your name or ours.
A 3-person, OffSec-certified team in British Columbia that tests what your clients run, delivers a graded report their developers and auditors can work from, and stays out of your client relationship.
Engagements from $5,000 CAD. Partner pricing on the rate sheet.
- OSCP
- OSEP
- OSWE
- OSMR
- BSCP
- CRTO
- OWASP Top 10
- OWASP ASVS
- OWASP Testing Guide
- NIST SP 800-115
- OSSTMM
- WASC
How it works with you
You keep the client. We do the testing.
- Your relationship, your invoice
- You scope with us or hand the client over for scoping. Either way you own the account, and you can bill the engagement through your own catalogue or have us invoice directly.
- White-label or co-branded report
- Your name on the cover, ours, or both. The content is the same graded report either way, with every finding carrying a CVSS vector, a CWE classification and reproduction steps.
- A turnaround fixed at scoping
- Dates are agreed in writing before work starts, so you can pass them to your client as a commitment rather than an estimate.
- Retest included
- One retest round of the reported findings, within 60 days of the report, at no extra charge. Your team or theirs remediates; we confirm closure.
- No unsolicited contact with your clients
- We do not sell to your clients, and we do not contact them without your approval. Where direct contact helps, such as a scoping call or a findings walkthrough, it happens with you in the loop.
What we test
6 services, all manual.
-
Web Application Testing Manual testing of your application's authenticated and unauthenticated attack surface, aligned to OWASP ASVS.
-
Mobile Application Testing iOS and Android testing that treats the app as untrusted, because in an attacker's hands it is.
-
External Network Testing What an attacker on the internet can see, reach and exploit before anyone at your company notices.
-
Internal Network Testing We assume the perimeter already failed, then find out how far that gets someone inside your network.
-
API Testing Your API is the real application. We test it directly, with every client-side restriction removed from the path.
-
Cloud Security Testing Azure and AWS environments tested the way an attacker holding one leaked key would use them, not the way the diagram says they work.
Why your clients are asking
The questions have already started.
- Cyber-insurance renewals
- Renewal questionnaires increasingly ask whether a penetration test was performed in the last year, and some carriers want the report rather than a yes. Requirements vary by carrier and policy.
- SOC 2 and ISO 27001
- Auditors generally look for independent testing inside the audit period. A test scheduled after the period closes does not help.
- PCI DSS 4.0.1
- Requirement 11.4 calls for internal and external penetration testing at least every twelve months and after significant change.
- Enterprise procurement
- Security questionnaires arrive before the contract does. A current report covers the technical testing questions; the rest is policy, and that is where you come in.
What you get
For you, and for your client.
What a partner receives
An anonymised sample report, a plain-language explainer you can hand to a client, a scoping checklist for each service, and one person to call: the tester who will run the work, not an account manager.
What a client receives
An executive summary, an overall A-to-F risk grade for the tested scope, every finding with its CVSS vector, CWE classification and reproduction steps, proof-of-concept evidence, remediation written against their stack, and a retest summary once fixed.
Getting started
Four steps to the first engagement.
- A 20-minute call What your clients run, what they are being asked for, and how you want to bill it.
- Partner rate sheet Pricing per service with room for your margin, and the partner agreement.
- First scope Targets, roles and exclusions agreed in writing, with dates you can pass on.
- Report and retest Delivered under your name or ours. One retest round of the reported findings within 60 days.
Request the partner rate sheet
Tell us what your clients run and how you would want to bill it. We reply within one business day with the rate sheet and the partner agreement.
Also worth reading