Security is not a condition a company arrives at. It is a set of claims that were true on the day someone last examined them, and that quietly stop being true afterwards, without announcing it. This service exists to establish those claims as fact, in writing and under test — and then to establish them again, so that what you tell your insurer, your client or your board remains as true on the day it is read as it was on the day it was written.
The question arrives before you are ready for it
There comes a point when someone asks a company to demonstrate, rather than describe, the state of its defences. It arrives in one of three forms, and rarely with much warning: the insurer at renewal, with a questionnaire that must be answered in writing and signed; a larger client, whose procurement department has begun asking its suppliers the questions its own auditors ask of it; or the question from inside, usually after a company in the same trade has had a difficult month.
In each case the answers are given from memory, from a vendor’s dashboard, or from what the IT provider said the last time anyone enquired. All three describe what was intended. None describe what a test would find, and the difference is not academic. Insurers have contested claims on precisely that ground: a control genuinely in place, genuinely believed to be universal, and absent from the one path the attacker used. The policy was not the problem. The answer was.
What is produced
Ten working days, one site, one perimeter. It results in a single document — the Verification Report — in which every line has the same four parts:
- The claim
- Something you stated, in writing, before anything was measured.
- The method
- Precisely how it was tested.
- The evidence
- The raw output, retained unmodified.
- The verdict
- One of three, and only three:
Contradicted
Not tested
The third deserves a word, because it is unusual to see it written down. Not tested means a claim was not verified; it does not mean the claim is sound. A report containing no such lines is asserting a coverage it does not possess, and an experienced reader will notice. We would rather hand you a document with visible gaps than one that quietly implies there are none.
What is deliberately excluded
This is not a penetration test, and not a forensic examination. It is not monitoring, and it does not produce a certificate.
It is also not remediation. We do not repair what we examine — not as an option, not for an additional fee, not at any point. The reason is straightforward: an assessor who also sells the repair has an interest in finding one. Where something needs putting right, it goes to whoever already looks after your systems, and we remain in a position to verify their work afterwards, which we could not do had we performed it ourselves.
These limits are not modesty. A document that states plainly what it did not examine is considerably harder to attack than one which implies it examined everything, and that distinction matters most on the day you are asked to defend it.
How it proceeds
Your declaration comes first. Before any measurement, you set out in writing what you believe to be true: what is exposed and what is closed, what is logged and where those logs go, what is backed up, who holds administrative access, and in which timezone your operations run. This is signed before we begin, and the order is not a formality. A finding recorded against a claim you never made is an opinion; a finding recorded against a claim you did make is a verification.
Measurement from outside requires no access at all. It establishes what is reachable from the public internet, which administrative interfaces are visible, which certificates are actually presented to a visitor and whether an ordinary client would accept them, and what your DNS and mail posture reveals.
Evidence from configuration requires read-only access. Rules are compared against stated intent; administrative accounts are enumerated; log destinations are followed to see whether anything receives them; signature freshness and patch level are established; and configuration is fingerprinted, so that from the second engagement onward, drift becomes measurable.
Active proof takes place in a scheduled window, with your written approval and a rollback prepared in advance. This is the part that distinguishes the exercise from a questionnaire, and it is short: traffic is sent to a port that is supposed to be closed, and the block is observed; intrusion detection is triggered under controlled conditions, and the response is observed; a backup is actually restored; a log is followed to its destination and found there, or not.
Jurisdiction and ownership close the engagement. Who owns each component of the stack that defends you, under which legal system it operates, where its management plane resides, and where its telemetry is sent. Geographic location and legal jurisdiction are not the same thing, and a review that treats them as interchangeable will reassure you about something you were not asking.
We began with ourselves
Before offering this to anyone, we ran the full method against our own production infrastructure. The backup control reported success every morning. Archives were produced on schedule, at the expected size, listed correctly, and copied to off-site storage. The daily confirmation was accurate in everything it said: it counted files, and it counted objects.
Then one of those archives was opened.
meta.xml <Databases/> <-- empty element SQL dumps none production 122 tables
It contained the site’s files, its certificates and its mail, and no database whatsoever. A restoration would have produced a complete and entirely empty installation. Three of the four sites holding data were in that condition, and had been for months. Every automated check had passed, because every automated check was measuring the container rather than its contents.
External measurement could not have found this, and neither could a compliance platform reading an API. The archive existed, it was the right size, and it appeared in every report. Only opening it answered the question.
That report is available on request, in full — including the two findings that were errors of the assessor rather than faults of the system. We publish our own corrections, which is the least one can ask of a document that claims to establish facts.
Terms
The engagement is charged, and this is deliberate. A complimentary security assessment is an instrument of sale, and everyone in the room understands it as such. One that is paid for is an opinion — and what makes it independent is that you commissioned it, and that we neither operate, resell, nor repair any part of what we examine.
A report that is never repeated becomes a document. A report that is repeated is a control.
If a questionnaire is already on your desk
Send it. We will tell you which of its questions this engagement can answer, which it cannot, and where the difference lies — before you commit to anything at all.