Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Sample deliverables

See the report before you buy it.

Most firms describe the deliverable and show it to you at the end. These are the actual formats, as PDFs, produced by the same generators that make a real client's documents. No email, no form, no call first.

Penetration Test Report

PDF · 15 pages

A web application test with nine findings, from a critical authorization flaw down to informational. Every finding carries the request and response that produced it, the log lines showing the control that never fired, steps to reproduce it, and separate evidence proving the fix works on retest.

  • Coverage table naming nine test areas, what was done in each and the result, so an area with no findings reads as tested rather than skipped
  • Method aligned to the OWASP Testing Guide and the Penetration Testing Execution Standard
  • Severity colour coded throughout, with the full CVSS vector beside our own rating
  • Request and response pairs, application logs and enumeration results under each finding
  • Retest evidence proving each fix, and what the report does not claim

Phase 1 Gap Assessment

PDF · 25 pages

A SOC 2 readiness assessment across four Trust Services Categories, assessing all 56 criteria in scope individually. Ten numbered sections, a per-criterion register, a findings register the criteria table cross-references, and a remediation roadmap.

  • Engagement decisions taken at kickoff, and the state definitions every position is judged against
  • Executive summary with the headline counts, then position by control family
  • Every criterion assessed individually: state, observation, and a cross-reference to the finding it raised
  • Findings register with severity, state and the criteria each one affects
  • Remediation roadmap grouped by what it costs to close, plus the policies and artifacts the gaps require

Security Assessment Attestation

PDF · 4 pages

The signed letter issued after a security engagement, for a customer, an insurer or a buyer who asks what was done. It states the scope, the dates, what was found, what was fixed and verified, and in plain terms what the letter does not claim.

  • What was tested, and the boundary around it
  • What was found by severity, and what was remediated and independently verified
  • What the letter is not: no audit opinion, no certification, no accredited attestation
  • The signature block as issued
  • A specimen mark on every page and across the signature itself
All three are specimens. The client, the systems, the findings and the dates in these documents are invented for illustration, and every page says so. The attestation letter carries a specimen mark across every page as well, because a short signed letter is the one document here somebody might try to pass off as real. Nothing in either report describes a real organisation, a real engagement, or a real vulnerability in anyone's software. What is real is the structure: the sections, the ordering, the level of detail and the way a finding is written.

Wondering how to read one? What a security deliverable actually looks like walks through both, and what separates a report worth paying for from a tool export with a logo on it.

Want one of these about your own systems?

A free call, and we will tell you which of the two you actually need, including when the answer is neither yet.

Book a free readiness call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.