Skip to main content
Authorized testingSoftware Development

Software assurance — black, grey, and white box

How we look at a system that already exists. Outside-in, authenticated, or source-assisted. We cut the surface, then we attack the boundaries. No scan without a signed SOW.

Most businesses have never seen their own system the way an attacker, a logged-in user, or a senior engineer with the source would see it. They have a scan PDF, or a hope. Software assurance is the look — scoped, authorized, and written so the people who own the system can act.

We do not sell exam terms as products. Boundary-value analysis and equivalence partitioning are how we cut the surface: the inputs that behave the same, and the edges where they stop. Then we attack those. Black box, grey box, and white box are how much of the system we are allowed to see while we do it.

How we engage

To start
$4,999
Then
$175 / hour
Plus
API usage and any cost associated with the work is billed through. We do not mark it up as a surprise line — it is named in the proposal.
Horizon
typically 4–6 months
After
Software care from $999 / month · Software care & marketing from $1,999 / month

Three ways to look

Black box is the stranger on the public internet — no source, no credentials, no server access. That is the External Exposure Report: forgotten subdomains, stale staging, exposed files, secrets in the bundle, whether row-level security holds when the API is hit directly.

Grey box is an authenticated assessment. You give us a role. We walk the paths a real user can reach — the object they should not see, the action they should not take, the state that breaks when two values meet at the edge. White box is source-assisted: we read the code, then we prove what the code allows. It pairs with the AI-built codebase audit when the app was shipped fast and nobody has read every line.

How we cut the surface

A system is too large to poke at random. We partition inputs into classes that behave the same — the same role, the same form, the same boundary — and we test a representative of each class. Then we test the edges: the empty value, the one-too-many, the user who is almost allowed. That is equivalence partitioning and boundary-value analysis, said in the language of the work.

The output is a written packet: what we tried, what we found, the confidence on each finding, and the remediation step. A second engineer with the same access should be able to reproduce it.

Authorization first

We begin no scanning of any kind until a scope of work is countersigned and the target is confirmed yours to test. If the host is a third party, their policy is part of the scope. Testing systems you are not authorized to test is a crime. A firm that is casual about that will be casual with your systems too.

Reconnaissance that only observes what is already public can start once ownership is confirmed. Anything that probes — authenticated traffic, fuzzing at a boundary — waits for the written go. We do not run aggressive scans against a live production system without your explicit sign-off.

What this is not

This is not a certificate. We do not wave OSCP, GPEN, or CEH as a substitute for the work. This is not cyber-insurance. This is not a promise that the system is free of vulnerabilities — it is a dated, scoped look at the surface you asked us to see.

Continuous exposure monitoring attaches after the first report if you want the outside-in pass to run again as you ship. Fuller authenticated or source-assisted work is scoped as its own engagement under Software terms.

FAQ

Common questions.

Is this a penetration test?
It is authorized testing of a system you own, at an agreed depth. Black box is the external, unauthenticated portion. Grey box adds a real login. White box adds the source. We will use the word penetration test in the SOW when that is the engagement. We will not use it as decoration on a scan PDF.
Will you take the site down?
Default reconnaissance only observes what is already public. Anything that probes is scheduled, scoped, and signed. We do not run aggressive scans against production without your explicit go.
Do I need to prove I own the system?
Yes. Written, countersigned authorization, and confirmation the target is yours. If a host's policy applies, it is in the scope.
How much does software assurance cost?
Software Development starts at $4,999. Hours are $175 after that. API usage and any cost associated with the work is billed through. We do not mark it up as a surprise line — it is named in the proposal. Typical horizon is typically 4–6 months. After launch, software care from $999 / month, or software care & marketing from $1,999 / month. Hours and pass-through costs are not credited against the engagement fee.
How is this different from the exposure report or the codebase audit?
The exposure report is black box. The codebase audit is an inside-out read of generated or existing source. Assurance is the program that chooses the depth — and, when you want it, combines them — under one authorization and one written packet.