About

Authorized assessment. Clear answers.

For CEOs, founders, and IT leaders who need a straight answer: what can an outsider reach, and what should we fix first?

We start with a free non-invasive Brief when useful, then run paid assessments only under written authorization. Deliverables emphasize business impact and next steps — calm process, no scare tactics.

How an assessment runs

  1. Confirm ownership, scope, and written authorization (rules of engagement)
  2. Assess only the agreed surfaces in an isolated engagement setup
  3. Validate carefully — evidence first, no destructive testing
  4. Report in business language, then remediation discussion and bounded retest

Confidentiality and evidence

Client data and evidence stay inside the engagement. We minimize what we collect, protect artifacts during the engagement, and tear down engagement environments when work ends. We do not publish client findings.

Authorization and rules of engagement

The Free Brief is a passive public-surface orientation. Active assessment starts only after qualification and written authorization from someone who can approve testing on the listed domains. Rules of engagement define in-scope hosts, methods, and out-of-bounds activities before paid work starts.

Where we work

We primarily serve European and North African B2B SaaS and digital businesses with production web applications — remote delivery under agreed time zones.

Our operating principles

  • Work only with clear authority — never probe domains you cannot approve
  • Stay non-destructive — no availability abuse or social engineering on Outside-in
  • Keep the Free Brief thin — unpaid deep reconnaissance belongs in a scoped assessment

Engagements: engagements@truehat.net