

Three things help most: a clear scope document listing the assets to be tested, a test environment isolated from production where possible (or a maintenance window if production is in scope), and an internal point of contact who can respond to questions during the engagement. For Web3, share the repository commit hash you want tested and any deployment addresses. For AI/LLM systems, share the system prompt and any RAG sources. We provide a scoping checklist after the first call.
Most engagements run 2 to 4 weeks end-to-end. A small single-application scope can close in 1–2 weeks. A complex multi-environment engagement (web + API + cloud + AD) typically takes 3–4 weeks of testing followed by 3–5 days of peer review and consolidation. Smart contract audits are scoped by code complexity rather than duration — we quote both.
A fixed-floor base fee covering the scoping, four auditors' base time, peer review, and report production — plus a per-finding bonus weighted by severity (Critical / High / Medium / Low / Informational, CVSS 3.1). The bonus structure is disclosed in your quote so you can model the upper bound. In practice, engagements typically land 10–30% below the cap because not every codebase has a long tail of medium and low findings. You can also use our price calculator for an indicative range.
For web and infrastructure: PTES (Penetration Testing Execution Standard) and OWASP testing guides as the backbone, MITRE ATT&CK for adversary emulation when relevant. For mobile: OWASP MASVS and MSTG. For APIs: OWASP API Security Top 10. For smart contracts: a hybrid of SWC Registry, Trail of Bits' "Building Secure Contracts", and our internal Web3 checklist. For AI/LLM systems: OWASP LLM Top 10 and MITRE ATLAS. The applicable methodology is named in your engagement letter and your final report.
Yes. Our reports are written to the format that ISO 27001 certification bodies, SOC 2 CPA firms, PCI QSAs, and DORA-supervisory authorities expect to receive. They include executive summary, methodology, scope, findings with CVSS scoring and remediation guidance, evidence appendices, and retest verification of closed items. If your specific auditor has a custom format requirement, share it during scoping and we will accommodate.
Yes, for findings remediated and resubmitted within 30 days of the preliminary report. The retest specifically verifies closure of the reported issues — it is not a fresh end-to-end engagement. If new functionality has been deployed since the original test and you want it covered, that is a scope extension at the per-finding bonus rate (without the fixed base fee).
Yes, separately from standard pentesting. Red-team engagements have different scoping, longer timelines (typically 4–8 weeks), and a different deliverable focus (blue-team detection and response capability) compared to vulnerability-focused pentests. For DORA TLPT and TIBER-EU engagements specifically, ask for our threat-led testing brief.
It is escalated to your engagement point of contact within hours, not weeks. We do not sit on critical findings until the final report. You receive a preliminary write-up with reproduction steps and an immediate mitigation recommendation so your team can act before the testing window even closes.