Security that stands up to scrutiny.

Penetration testing, security posture and AI governance for small and mid-sized businesses — in plain language, at a fixed price.

  • Fixed price, quoted up front
  • Written authorization before any test
  • Reports you can forward as-is

What we do

Three things, done properly.

Most firms lead with whichever one is easiest to sell. These get equal weight because they solve different problems.

AI

Rules for using AI, and security for the AI you build or buy.

Your staff are already using these tools, whether or not there's a policy. We set what can go into a chatbot and what can't, review where that data actually ends up, and cover the AI and ML systems you build, buy or expose to customers.

  • Acceptable-use policy people will actually follow
  • Written AI/ML security policy
  • Data-flow review for public AI tools
  • The questions to ask a vendor before you sign

Not model building, MLOps platform work, or vendor negotiation.

Cyber security

Your security posture, written down and defensible.

Most small businesses have reasonable security and no way to prove it. That becomes a problem the day a large customer sends a forty-page questionnaire or an insurer asks what controls you have.

  • Questionnaires completed, with evidence per line
  • Policy set: access, passwords, backups, incident response
  • Gap review ranked by what to fix first
  • A remediation plan your IT provider can action

Not software resale, managed IT, or a certification we can grant.

Penetration testing

We attack your network, on purpose, and tell you what worked.

A test answers one question: what can someone reach, and what can they do once they're in. We test from outside your perimeter and from inside your network, then show you exactly how we got there.

  • External testing — what the internet can reach
  • Internal testing — what someone on your LAN can reach
  • Findings ranked by real risk, not scanner output
  • Two write-ups: plain-language and technical

Not a scanner export. Network testing only — not web app, cloud, wireless or physical.

Straight answers

You probably arrived with one of these.

Pick the one that sounds like your week. Nothing to fill in.

What's actually happening

Your customer's procurement team has to prove they checked their suppliers. Most of the questions ask whether you have written things down — not whether you own expensive software.

What we'd do

Read the questionnaire, tell you which answers you already have, write the ones you don't, and put evidence behind each line.

What it isn't

It is not a penetration test. If someone quotes you one for this, ask them why.

Ask about this →

What's actually happening

Staff use whatever tool makes the day easier. Without a written rule, "don't paste customer data into a chatbot" is a preference, not a policy — and nobody can point to it.

What we'd do

Write an acceptable-use policy short enough that people actually follow it, review where your data goes when those tools are used, and cover any AI system you build, buy or expose to customers.

What it isn't

It isn't blocking AI. Blanket bans get routed around within a week.

Ask about this →

What's actually happening

An insurer or a large customer wants evidence that someone tried to break in and wrote down what happened. A vulnerability scan is not that, though plenty of firms sell one as if it were.

What we'd do

Test from outside your perimeter and from inside your network, then report what we reached and how — with steps to reproduce. Nothing is scanned until you've signed a scope naming the exact addresses, dates and limits.

What it isn't

It isn't a scanner report with the logo changed.

Ask about this →

What's actually happening

Nothing has gone wrong. Someone has asked you a question you've never had to answer, and most small companies are in exactly the same position.

What we'd do

Start with a call, at no charge, to work out which of the three things above you actually need. Often it's one, not all three.

What it isn't

It isn't a retainer. If one piece of work closes it out, we'll say so.

Ask about this →

How it works

Four steps. Your part is the short one.

  1. 01

    Send a question

    Forward the questionnaire, the insurance requirement, or the thing your team keeps asking. We reply with what it means and what it takes to close it out.

  2. 02

    A call, then a fixed price

    Thirty minutes, free, no deck. You get a written scope: what's covered, what isn't, what you receive and what it costs. A change in scope means a re-quote, never a surprise invoice.

  3. 03

    Written authorization

    For penetration testing this is not optional and never rushed. Nothing is scanned before you've signed a document naming the exact address ranges, the dates and the limits of the test. It protects you legally and it protects us — and any tester willing to skip it is telling you something about how they work.

  4. 04

    The work, then plain-language findings

    A report written for the person who has to act on it, plus a walkthrough call. Ask what a finding means as many times as you need — that's the job.

How we work

The parts most firms leave out.

Fixed price, up front

Quoted in writing before anything starts. No hourly meter.

Nothing to resell

We don't sell hardware or software, so there's nothing we're steering you toward.

Plain language

If a report needs a translator it isn't finished. Forward ours to a customer as-is.

We'll say when you don't need us

Some questionnaires you can answer yourself in an afternoon. We'll tell you which parts.

Send us the thing you're stuck on.

We'll tell you what it means and what it takes to close it out. No charge to ask, and no pitch attached.

Email us

One reply, from the person who'd do the work. No call unless you want one.