Red Team · engagement type

Social engineering with consent.

Optional engagement, only with written authorization from the business owner. Simulated phishing emails, voice-phishing scripts, badge / tailgating attempt at a single physical entry. Captures click-through and credential-submission rates without ever capturing the actual credential.

What's tested

The hard ethical guardrails

Critical: we never capture an actual credential. The phishing landing page collects "credential submitted: yes/no" and the username (so you can target retraining), NEVER the password. The username + a non-credential token is what hits our log. The actual password the user typed is discarded by the browser before our page receives it.

What you get

Pricing

Phishing-only: from $1,200. Email + landing page, up to 50 employees, 3 templates. 2 weeks elapsed.
Phishing + vishing combo: from $1,800. Adds 5-10 vishing calls during the engagement window.
Full social-eng package: from $2,500. Phishing + vishing + smishing + 1 tailgating attempt + USB drop.