How we work
A disciplined engagement, every time.
The same five stages on every project, whatever the target — so you always know what is happening, what you'll receive, and that the fix was proven. Manual-led, evidence-backed, and aligned to the standards your auditors recognise.
Scope & threat-model
Before any testing, we agree objectives, targets, rules of engagement, testing windows and emergency contacts in writing. We threat-model your environment so effort goes where real risk is, and you get a fixed timeline and quote.
- Objectives and success criteria
- Assets, environments and exclusions
- Rules of engagement and safety limits
- Named contacts and escalation path
Recon & mapping
We map the real attack surface — the application logic, trust boundaries, roles, APIs and infrastructure — the way an attacker studies a target before touching it. Automated tooling speeds this up; humans decide what matters.
- Attack-surface enumeration
- Authenticated role mapping
- Technology and dependency profiling
- Business-logic understanding
Manual exploitation
The core of the work. Senior testers exploit by hand, chaining weaknesses into demonstrated impact rather than reporting isolated issues. Every step is logged so findings are reproducible and safe.
- Manual testing against OWASP / PTES
- Chained, multi-step exploitation
- Safe proof-of-concept, no destructive actions
- Critical issues flagged same-day
Report & debrief
You get an executive summary for leadership and a technical report your engineers can act on — severity, evidence, reproduction and a concrete fix for every finding — walked through in a live debrief.
- Executive and technical reporting
- Reproduction steps and evidence
- Risk-ranked, developer-ready fixes
- Live walkthrough with your team
Retest & verify
Included as standard. Once you've fixed the issues, we test them again and confirm in writing what is closed — so you have evidence for customers and auditors, not just a finding count.
- Verification of each remediation
- Written retest letter
- Evidence for ISO 27001 / SOC 2 / PCI / DORA
- Closure, not just discovery
Standards we align to
We don't reinvent methodology. We follow the recognised frameworks and map findings to the controls you report against.
OWASP
WSTG, MASTG and the API Security Top 10 for web, mobile and API testing.
PTES
The Penetration Testing Execution Standard for overall engagement structure.
OSSTMM
Open-source security testing methodology for network and infrastructure work.
MITRE ATT&CK
Adversary techniques mapped on red team and detection engagements.
NIST SP 800-115
Technical guide to information-security testing, for process rigour.
CVSS / EPSS
Consistent, defensible severity scoring across every finding.
Tools speed us up. They don't test for us.
We use commercial and open-source tooling — and we write our own — to cover ground quickly and consistently. But a scanner can't understand your business logic, chain weaknesses, or tell a real risk from noise. That judgement is why you hire people, and it's where our findings come from.
It's also why we build and release our own software, like Blackbar and Airward: the same engineering mindset we bring to your assessment.
- Manual-ledPeople find the bugs that matter; tools handle the breadth.
- ReproducibleEvery finding comes with the steps to reproduce it.
- Safe by defaultNo destructive techniques without explicit authorisation.
- Standards-mappedFindings tie back to the controls your auditor asks about.
See it on a real target.
Want to know what you'd actually receive? Read an anonymised sample report, browse case studies, or just tell us your scope.
Every engagement includes
- Delivered by
- Senior PXL Security engineers
- You receive
- Executive summary, technical report, retest letter
- Retest
- Included as standard
Let's scope your engagement.
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.