Get in touch

Tell us what you are running.

Engagements start with a short call — usually thirty minutes. What you have built, what is worrying you, and whether we are the right people for it. If we are not, we will tell you, and where we can we will point you at someone who is.

There is no form here and no chat widget. A site that sells security review should not be loading a third-party script to collect your details.

Vulnerability disclosure

Found something in ours?

We spend most of our week doing this to other people's systems, so we are not going to be precious about our own. If you have found a security issue in this site or anything else we operate, we want to hear about it.

We acknowledge within one business day. We will not involve lawyers, we will not argue about severity to avoid crediting you, and we will name you in the fix unless you would rather we did not.

What happens next

  1. You write, we reply

    Within one business day, with either a question or a time to talk.

  2. A scoping call

    Thirty minutes, no deck. We are trying to establish whether the work is real and whether we are the right people for it.

  3. A written proposal

    Fixed fee, fixed window, named deliverable, and an explicit statement of what is out of scope.

  4. Or an honest no

    If we are full, or it is not our expertise, you will hear that at step two rather than after a month of proposal cycles.