Most businesses have never seen their own system the way an attacker, a logged-in user, or a senior engineer with the source would see it. They have a scan PDF, or a hope. Software assurance is the look — scoped, authorized, and written so the people who own the system can act.
We do not sell exam terms as products. Boundary-value analysis and equivalence partitioning are how we cut the surface: the inputs that behave the same, and the edges where they stop. Then we attack those. Black box, grey box, and white box are how much of the system we are allowed to see while we do it.
How we engage
- To start
- $4,999
- Then
- $175 / hour
- Plus
- API usage and any cost associated with the work is billed through. We do not mark it up as a surprise line — it is named in the proposal.
- Horizon
- typically 4–6 months
- After
- Software care from $999 / month · Software care & marketing from $1,999 / month
Three ways to look
Black box is the stranger on the public internet — no source, no credentials, no server access. That is the External Exposure Report: forgotten subdomains, stale staging, exposed files, secrets in the bundle, whether row-level security holds when the API is hit directly.
Grey box is an authenticated assessment. You give us a role. We walk the paths a real user can reach — the object they should not see, the action they should not take, the state that breaks when two values meet at the edge. White box is source-assisted: we read the code, then we prove what the code allows. It pairs with the AI-built codebase audit when the app was shipped fast and nobody has read every line.
How we cut the surface
A system is too large to poke at random. We partition inputs into classes that behave the same — the same role, the same form, the same boundary — and we test a representative of each class. Then we test the edges: the empty value, the one-too-many, the user who is almost allowed. That is equivalence partitioning and boundary-value analysis, said in the language of the work.
The output is a written packet: what we tried, what we found, the confidence on each finding, and the remediation step. A second engineer with the same access should be able to reproduce it.
Authorization first
We begin no scanning of any kind until a scope of work is countersigned and the target is confirmed yours to test. If the host is a third party, their policy is part of the scope. Testing systems you are not authorized to test is a crime. A firm that is casual about that will be casual with your systems too.
Reconnaissance that only observes what is already public can start once ownership is confirmed. Anything that probes — authenticated traffic, fuzzing at a boundary — waits for the written go. We do not run aggressive scans against a live production system without your explicit sign-off.
What this is not
This is not a certificate. We do not wave OSCP, GPEN, or CEH as a substitute for the work. This is not cyber-insurance. This is not a promise that the system is free of vulnerabilities — it is a dated, scoped look at the surface you asked us to see.
Continuous exposure monitoring attaches after the first report if you want the outside-in pass to run again as you ship. Fuller authenticated or source-assisted work is scoped as its own engagement under Software terms.