How an engagement runs

Every engagement is scoped and led by David Porcello. Here’s what that looks like from start to finish.

The process

Every engagement follows the same phased approach. The timeline below is typical for a single application or network; larger scopes run longer, but the shape stays the same.

  1. Scoping call

    A 30-minute conversation about what you're protecting and what you're looking to accomplish with a pentest. You'll leave with a clear recommendation.

    When: Within a week of initial contact

  2. Proposal and rules of engagement

    We'll send a short written proposal: targets, approach, testing windows, exclusions, points of contact, and a fixed price. Once signed, that document governs the engagement.

    When: Within a few business days of scoping call

  3. Project kickoff

    Credentials, access, and any architecture context are exchanged over secure channel. Testing dates are confirmed and you get a direct line for the duration.

    When: As soon as 2-3 weeks after proposal is signed

  4. Testing kickoff

    Testing proceeds against the agreed scope. Anything critical is reported the day it's found, not held for the report. Regular status updates are available on request; otherwise you hear from us when something matters.

    Duration: Typically one to three weeks depending on scope

  5. Report and readout

    A written report with an executive summary, methodology, and findings that each include reproduction steps, evidence, business impact, and remediation. Executive and engineering team reviews available on request.

    When: Within a week of test completion

  6. Retesting

    Once you've fixed what matters, the affected findings are retested and the report is updated to reflect the new state. 90 days of retesting included in every engagement.

    When: On your schedule, within 90 days of test completion (extensions available on request)

Methodology and standards

We follow established frameworks to ensure results are measurable, auditable, and standards-based, including OWASP Web Security Testing Guide (WSTG), Application Security Verification Standards (ASVS), and GenAI Security Project for AI/LLM implementations.

These frameworks define the floor, not the ceiling. Every finding is validated by a real human, and severity is based on demonstrated business impact in your environment.

What our reports contain

  • An executive summary for leadership and audit stakeholders
  • Scope, methodology, and rules of engagement
  • Detailed findings prioritized by risk severity
  • Reproduction (PoC) steps, evidence, and business impact
  • Remediation steps and implementation guidance

Handling your data

Credentials, evidence, and findings are securely exchanged, encrypted for the duration of the engagement, and deleted on a schedule agreed in the rules of engagement. Testing infrastructure is dedicated per engagement and any tooling that processes client data is documented in every proposal.

Who does the work

Every engagement is scoped and led by David Porcello. When scope calls for more hands, a small circle of vetted senior testers works under his direct supervision, following the same methodology, with every finding reviewed before it reaches you.

Pricing

Fixed price per engagement, quoted after the scoping call. Because there’s no sales team, no project-management layer, and no junior bench to bill for, we provide quicker turnarounds and more value than many larger firms.