Skip to content

Zero Harbor Security · Atlanta metro, Georgia

Human-Led Penetration Testing

OSCP- and CISSP-certified offensive security, paired with production engineering from inside AWS, a top-ten US bank and a Fortune 500 insurer. A decade each, and you meet all of us.

The deal is signed off. Their security review is the last thing standing. They want a current third-party test with a real name on it. That is the test this firm runs.

$12,000
Fixed fee
10 days
From authorisation
1 retest
Within 30 days

A scanner can tell you what is exposed. It cannot tell you what that is worth.

The findings that stop a deal are rarely a missing patch. They are a permission boundary that holds in the interface and not at the API, or three low-severity issues that chain into one critical. Those need somebody who understands what your system is supposed to do.

5 days end to end

A person tests it. A person signs it.

Tooling runs coverage because it is genuinely better at breadth. The billed hours go into exploitation, chaining findings together, and the access-control and business-logic flaws no scanner models. The attestation carries the name of the operator who did the work.

10 business days, from authorisation

A date your deal can be planned around.

Quoted from signed authorisation rather than from first contact, because scoping and your own legal review are not ours to control.

“Simply running an automated tool does not satisfy the penetration testing requirement… The penetration tester must interpret the results of any automated tools and determine whether additional testing is needed.”
PCI Security Standards Council · Penetration Testing Guidance v1.1 · §4.1

The work

This is what a finding looks like.

Here is the shape of what gets delivered: the classes that stop enterprise deals, written the way they arrive. A location you can check, an impact stated in business terms, and a rating a reviewer can act on.

Findings summary · illustrative

1 Critical 1 High 1 Medium 1 Low
critical

Tenant isolation bypass in the reporting API

GET /api/v2/reports/{id}

An authenticated user of one tenant could read another tenant’s reports by changing a single identifier. Exploited end to end and reproduced in the report.

high

Role check enforced in the interface but not at the API

PATCH /api/v2/members/{id}/role

A standard member could grant themselves administrator rights by calling the endpoint directly.

medium

Password reset token does not expire on use

POST /auth/reset

A token captured from a forwarded email stayed valid indefinitely, allowing account takeover long after the legitimate reset.

low

Session cookie missing SameSite attribute

Set-Cookie: session

Widens the window for cross-site request forgery where another finding provides the entry point.

Illustrative findings, written to show the format. They are not drawn from any client engagement. Work delivered for a client belongs to that client.

Read the full sample report · PDF, 10 pages →

What you receive

Six documents, and what each one is for.

A penetration test report is worth exactly what the person reading it will accept, and that person is rarely you. It gets forwarded to an assessor, or to a security reviewer at your customer, who was not in the room and cannot ask you a question.

Executive summary

Forwarded to your prospect’s security lead

One to two pages, written to be sent on without editing. This is the document that moves the deal.

Technical report

Read by your engineers

Every finding with evidence, a CVSS rating, the business impact and a specific remediation step. Not a scanner export.

Remediation status per finding

Read first by a reviewing engineer

What was fixed, what was accepted with a stated rationale, and what is outstanding.

Attestation letter

Filed by their reviewer

One page naming the operator who ran the test, with credentials and serial numbers, scope, method and dates. Usually the exact thing a security review is asking for.

Coverage record

Answers “what did you not test?”

What was checked and how, test by test, including the checks that found nothing. A clean result should still show the work.

Retest

Closes the finding, in writing

One retest, included: within 30 days of report delivery, against the original scope, re-verifying the findings in the original report.

How it runs

Ten business days, from signed authorisation.

Not from your first email. Scoping and your own legal review are not ours to control, so the clock starts where our responsibility does.

  1. 1

    Day 0

    Scoping call

    Within one business day of the introduction. Scope, boundary and exclusions agreed in writing.

  2. 2

    Day 0

    Authorisation

    Written authorisation signed by someone entitled to give it. The clock starts here, not at enquiry.

  3. 3

    Days 1–4

    Testing

    Automated tooling runs coverage. The billed hours go into exploitation and chaining.

  4. 4

    Day 5

    Reporting

    Findings written up, rated and evidenced. Executive summary drafted for forwarding.

  5. 5

    By day 10

    Delivery

    Report, executive summary and attestation letter delivered. Retest scheduled on request.

The date is quoted from signed authorisation, not from your first email, so it is a date this firm actually controls.

The full scope

Who signs

The name on the report is the person who ran the test.

The common failure in this market is not technical. It is being quoted a senior and delivered a junior, with a report signed by somebody who never touched the system.

Suhyun Smith

Lead operator

Breaks it · offensive security, a decade

Built the end-to-end penetration testing programme at Amazon Web Services, then three years on Amazon’s red team against shipping consumer hardware. Earlier, infrastructure, application and physical testing at a top-ten US bank, and formal product testing to NSS Labs, Tolly Group and ICSA Lab standards.

OSCP · CISSP · AWS Security – Specialty · CEH v9 · AWS AI Practitioner

Matthew Rachwal

Supporting operator

Builds it · production engineering, ten years

Seven years at a Fortune 500 insurer building REST services and release automation, and before that APIs normalising more than twenty million records a day. Not a penetration tester. The engineer who knows what a system was built to do, which is what makes a business-logic finding land instead of reading as a false positive.

AWS Developer – Associate

Credentials, serial numbers and the full record →

When not to

There are five reasons not to hire this firm.

Some of them are free alternatives. Naming them costs less than taking an engagement that was never going to help.

  • The questionnaire is the whole blocker

  • Your compliance platform already includes testing

  • The deal closes inside two weeks

  • You need continuous coverage

  • You are under about twenty-five people

Why each one, in full →

Send the scope, or the date the deal needs to close.

A scoping call within one business day, then a fixed price and a delivery date in writing. If the work is not a fit, we will say so and point you somewhere better.

Start a scoping call