Fixed Quote. No Hourly Billing.
Every engagement is scoped on a thirty minute call and quoted as one fixed price, agreed in writing before any work starts. It does not move unless you change the scope, and we do not bill by the hour. What the price actually depends on is set out below, so the call is a conversation rather than a discovery process.
What you receive
The same delivery standard on every engagement, offensive or compliance, whatever the size. The price is discussed on the scoping call and fixed in writing; what you get for it does not vary.
Find it before someone else does
Manual penetration testing, red teaming and code review across web, API, network, cloud, mobile, AI and smart contracts, with phishing simulation and dark web monitoring alongside. Every finding proved with a working exploit.
Every engagement includes:
- Manual testing across every role and interface in scope
- A working proof of exploit for every finding
- Access control, privilege and tenant isolation testing
- Business logic and workflow testing
- Coverage matrix showing exactly what was tested
- Executive summary and technical report, auditor-ready
- Developer-ready remediation for every finding
- Report walkthrough call with your engineers
- Retest of every finding within 90 days
- Letter of attestation after the retest
Cloud identity review, targeted source code review and threat model review are added where the scope calls for them, agreed during scoping and inside the fixed price.
Ready before the assessor arrives
Readiness against PCI DSS, ISO/IEC 27001, 42001 and 27701, SOC 2 Type 1 and Type 2, HITRUST, HIPAA, GDPR and the India DPDP Act.
Every engagement includes:
- Scope and applicability review before anything else
- Requirement-by-requirement gap assessment
- Control design and operating evidence review
- Prioritised remediation roadmap
- Policy and documentation review
- Readiness sign-off before your external assessor
- Re-review of the gaps you have closed
We do not issue the certificate. That comes from your QSA, a licensed CPA firm, HITRUST or an accredited body, and we work alongside whoever you choose.
Paid by Cryptocurrency, Stripe Payment or Bank transfer. Invoices are raised in USD unless agreed otherwise.
Everything we run
Every service, with how long a typical engagement takes. The price for any of them is agreed on the scoping call and fixed in writing before work starts.
| Service | Typical duration |
|---|---|
| Web penetration testing | 5 to 12 working days |
| API penetration testing | 4 to 10 working days |
| Network penetration testing | 5 to 10 working days |
| Phishing simulation | 2 to 4 weeks |
| Dark web monitoring & threat intelligence | Ongoing, monthly reporting |
| Red teaming | 3 to 6 weeks |
| Source code review | 5 to 12 working days |
| AI / LLM penetration testing | 5 to 10 working days |
| Mobile application testing | 5 to 10 working days |
| Thick client application testing | 5 to 12 working days |
| Cloud security review | 5 to 12 working days |
| Blockchain & smart contract audit | 1 to 4 weeks |
| Compliance and readiness | |
| PCI DSS readiness | Readiness |
| ISO/IEC 27001 readiness | Readiness |
| ISO/IEC 42001 readiness | Readiness |
| ISO/IEC 27701 (PIMS) readiness | Readiness |
| SOC 2 Type 1 readiness | Readiness |
| SOC 2 Type 2 readiness | Readiness |
| HITRUST readiness | Readiness |
| HIPAA readiness | Readiness |
| GDPR readiness | Readiness |
| India DPDP Act readiness | Readiness |
What changes the price
Two targets of the same apparent size can differ by a factor of three in effort. These are the variables that actually move a quote, so you can estimate roughly where you will land before you talk to us.
Offensive engagements
06- Roles and privilege levels
- More roles means more boundaries to cross. On any authenticated target this is the single biggest driver.
- Size of the tested surface
- Endpoints, hosts, screens or contracts, counted properly, including the undocumented ones.
- Tenancy and isolation
- Where one customer, tenant or account could reach another, isolation testing is added.
- Source and credential access
- Code and working credentials make testing faster and deeper. They usually lower the price rather than raise it.
- Environments
- Testing staging and production separately costs more than testing one.
- Reporting and retest needs
- Attestation letters, auditor-ready formats and additional retests are scoped up front rather than billed later.
Compliance and readiness
06- Frameworks in scope
- One framework or several, and how far they overlap. ISO/IEC 27001 and 27701 share most of their evidence; PCI DSS and SOC 2 share very little.
- Environment and entities covered
- How much of the organisation the requirements apply to, across systems, sites and legal entities.
- Assessment type
- PCI merchant level and SAQ type, SOC Type I or Type II, HITRUST e1, i1 or r2. Each changes the depth of evidence required.
- Control maturity
- An organisation with documented, operating controls is assessed far faster than one starting from nothing.
- Existing evidence
- Whether policies, risk assessments and prior audit output already exist in a form an assessor will accept.
- Depth of support
- Gap assessment alone, or gap assessment through to remediation and readiness sign-off before the external assessor.
Commercial terms
- Fixed price
- Agreed in writing after the scoping call. We do not bill by the hour, and we do not raise change requests mid-engagement unless you change the scope.
- Quotation validity
- Quotations are valid for 30 days from the date of issue. After this period, pricing and scope may be reviewed based on the project requirements.
- Payment schedule
- 50% at kickoff, 50% on final report delivery. Flexible payment terms are available for ongoing engagements.
- Currency
- Invoiced in USD. Clients paying from an Indian account can settle in INR at the rate stated on the invoice. Cryptocurrency is accepted on request; the coins, networks and conversion rate are agreed in writing before the invoice is issued.
- How to pay
- Bank transfer or cryptocurrency. Beneficiary details and SWIFT code, or a wallet address and network, are issued with the invoice.
- Taxes
- Any tax that applies is shown as a separate line on the invoice rather than folded into the quoted price.
- Retest included
- On an offensive engagement, one full retest of every finding within 90 days, included in the engagement price. On a compliance engagement, one re-review of the gaps you have closed before your external assessment.
- Retainers
- Engagements booked across a year in advance are priced below the sum of the individual engagements. Offensive and compliance work can be mixed within one retainer, and the terms are agreed on the scoping call.
Get a fixed number for your scope.
Thirty minutes on a call is enough for us to quote accurately. You are not obliged to buy anything.