Skip to content
kubepath Book a call
Menu

How we work, and what we never do.

You are giving us access to the thing your business runs on. Here is exactly how we handle it.

01

Before we start

  • NDA signed before you share anything technical
  • Written authorisation and scope: what is in, what is out, the test window and who to call
  • Named people. You know exactly who is doing the work
02

While we test

  • Staging preferred. Production only with written approval
  • No denial of service, load testing, social engineering or destructive actions unless agreed
  • Synthetic test accounts and data. We don't touch real customer records
  • A short daily note: what we tested, what we found, what is next
  • Critical issues reported the same day, not saved for the report
03

How we judge risk

  • Manual first. Tools give coverage; people find the logic and authorization bugs
  • OWASP WSTG, ASVS and API Security Top 10, CIS Benchmarks, SOC 2 Trust Services Criteria, ISO 27001 Annex A
  • CVSS scores plus real business impact, with scanner noise separated out
04

When we fix

  • Changes on a separate branch as pull requests, never pushed straight to main or production
  • Every security-sensitive change explained
  • Your key flows checked after each fix
05

After

  • Findings stay confidential and are never published
  • Test credentials and any data copies deleted at the end
  • Retest and closure letter for your auditor or customer
Book a call