Team and Reporting
Team

may perform the activities with its core-team members, external freelancers, and/or volunteers.

First point of contact for this assignment shall be:

The workflow of our penetration testing team is modeled on that of a Capture The Flag (CTF) team: has a geographically distributed team and we use online infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This enables us to invite the customer to send several technical people from their organization to join our team on a volunteer basis. Naturally, we extend this invitation to as well.

Throughout the course of the audit, we intend to actively brainstorm with about both the and the process. This is a continuous learning experience for both us and you. Also, in our experience, a tight feedback loop with the customer greatly improves both the quality and focus of the engagement.

Reporting

will report to on the . This report will include the steps it has taken during the test and the vulnerabilities it has found. It will include recommendations but not comprehensive solutions on how to address these vulnerabilities.

A sample Pentest report can be found here:

One of 's core principles is “Teach To Fish”, otherwise known as “Peek over our Shoulder” (PooS); We strive to structure our services so they can also serve as teaching or training opportunities for our customers.