Find the holes before someone else does

Authorized Security Testing

Engagement-based security testing performed only with written authorization and a defined scope. The goal is a clear, prioritized report of real findings and how to fix them — not scare tactics.

🔒 Written authorization required — always

All testing is performed only under written authorization for systems you own or are permitted to test. Before anything begins, we agree in writing on exactly what’s in scope, what’s off-limits, and the testing window. No unauthorized testing, ever — on any system, for any reason. Testing something you don’t own or don’t have permission to test isn’t a gray area; it’s illegal, and we won’t do it.

⚠️ What this is, honestly

This is a one-person hobby and second job, not a licensed, bonded, or insured penetration-testing firm — but it isn’t unqualified either: the person doing the work holds two college degrees (Miller-Motte College and Prosser School of Technology) and professional certifications for Network Operations & Security. What you get is real, careful, authorized testing from someone trained and certified for it, at hobbyist rates and hobbyist availability (evenings/weekends, by arrangement), with the tradeoffs explained plainly. If you need a formally certified, insured commercial pentest for a compliance requirement (PCI, SOC 2, HIPAA attestation, cyber-insurance audit, etc.), say so up front — that’s a different kind of provider, and I’ll tell you plainly if this isn’t the right fit.

Six engagement types

What we can test

Engagements are scoped to what actually matters for your business — you don’t need all six, and we’ll help you figure out where the real risk is before quoting anything.

🌐

External

Testing what the internet can see and reach: your firewall edge, exposed services, VPN, and internet-facing servers. This is usually the first engagement for a business that’s never been tested — it answers "what could a stranger on the internet actually get to?"

🖥️

Web Application

Your website or web app: login flows, forms, file uploads, session handling, and the logic behind them. This is where customer data and payment flows usually live, so it's a common starting point for businesses that take orders or store accounts online.

🏢

Internal

What happens if a laptop, an email account, or a single workstation is already compromised — how far could an attacker move inside your network from there? Internal testing checks lateral movement, shared drives, and internal privilege boundaries.

📶

Wireless

Your Wi-Fi posture: encryption strength, guest-network isolation, rogue access points, and whether a device in the parking lot could reach your internal network. A weak Wi-Fi setup is one of the most common ways an "external" attacker becomes an "internal" one.

📧

Phishing Simulation

Authorized staff-awareness testing — carefully controlled simulated phishing emails sent to your team with your sign-off, measuring who clicks and who reports it. The goal is a training opportunity, not a gotcha; results are used to improve awareness, not to punish anyone.

🎥

Camera / IoT

Review of cameras, smart devices, and other internet-connected hardware for default credentials, exposed management ports, and firmware that's fallen out of date — the same class of device many small businesses never think to test.

What you actually get

What’s in the report

A pentest report is only useful if you can act on it. Every finding is written in plain English: what we found, how we found it, why it actually matters to your business (not a generic CVSS score), and a concrete fix. Findings are ranked by real-world risk and exploitability — so you know what to fix this week versus what can reasonably wait for the next budget cycle.

We don’t pad a report with informational noise to make it look impressive. If we found three real issues, the report has three real issues, explained clearly enough that whoever handles your IT — us or someone else — can go fix them without needing a translator.

After the report

Remediation and retest

1. You get the findings

We walk through the report together, in language you can act on — no jargon dump left for you to decode alone.

2. You fix, we help

You (or your IT provider) apply the fixes on the priority order we handed you. We’re available to help implement or advise as needed.

3. We retest

We re-check the specific findings to confirm they’re actually closed — not just assumed fixed. You get a written confirmation of what changed.

Honest, on purpose

No scare tactics. No unauthorized testing.

We don’t sell fear

No security service can make a system "unhackable," and anyone who tells you otherwise is selling something. Our goal is to reduce real risk and give you a clear, honest fix list — not to scare you into a bigger invoice than the risk justifies.

Scope and consent, every time

Every engagement starts with a signed rules-of-engagement agreement covering exactly what’s tested, when, and how. Nothing outside that scope gets touched, and testing is coordinated with you to avoid disrupting your operations.

Questions

What people ask

Is security testing legal?

Yes — when it’s authorized. We only test systems you own or have written permission to test, with a defined scope agreed in advance. No unauthorized testing, ever.

Will testing break something or take down my systems?

We test carefully and coordinate timing with you in advance. The goal is to find real risk without disrupting your operations — if a test carries any risk of disruption, that’s discussed and agreed to as part of the scope before we start.

What size business is this actually for?

Small businesses that want to know where they actually stand — a single office, a shop with a POS system, a business running its own website or Wi-Fi. You don’t need an enterprise IT department to benefit from a scoped test.

How is this different from checking the Security Advisories page?

Security Advisories shows you what’s being exploited across the internet in general. Penetration testing checks whether those kinds of issues — or others specific to your setup — actually apply to your systems.

Ready to scope an engagement?

Tell us what you want tested and we’ll talk through scope, timing, and cost before anything is signed.