Call Scope a pentest
// AUTHORIZED · SCOPED · ETHICAL

We break in first.

Scoped, authorized penetration testing delivered by our certified senior testing partners - external, internal, web & cloud, named in every contract. We scope it with you, translate the findings into plain English, and manage the fixes: one accountable local contact, the right expert for each job.

Scope a pentest Email us
External & internal Web & cloud Toronto & the GTA
Illustrative only - every engagement is authorized and scoped in writing first.

// What we test

Where the real risk hides.

We test the places attackers actually go - the perimeter, the inside, your apps and your cloud - and the human layer that ties them together. Pick a focus or run the full picture.

External network

What an attacker sees from the internet - exposed services, weak edges and forgotten doors into your network.

Internal network

How far one foothold spreads - lateral movement, privilege escalation and the path to your most sensitive data.

Web & cloud apps

Auth flaws, broken access control, injection and risky cloud configs in the apps your business runs on.

Microsoft 365 / Google Workspace

The tenants where your email, files and identities live - MFA gaps, risky sharing and over-permissive access.

Social engineering & phishing

Authorized phishing and pretext tests that measure the human layer - by behaviour, never to shame anyone.

Wi-Fi (optional)

On-site wireless review - rogue access points, weak segmentation and guest networks that reach too far.


// How it works · Rules of engagement

Scope. Test. Report. Retest.

We only ever touch what you authorize, in writing. Before anything runs, there is a signed authorization, a defined scope, and clear rules of engagement - including hours, targets that are off-limits, and who to call. That is the ethical spine of everything we do.

01

Scope & authorize

We agree targets, methods, timing and limits, then put a signed authorization and rules of engagement in place. Nothing starts without it.

02

Test

We safely emulate a real attacker within scope - careful with production, in close contact, and ready to pause the moment you need us to.

03

Report

A clear executive summary plus a prioritized, technical findings list - what we found, why it matters, and exactly how to fix it.

04

Retest

Once you have remediated, we re-check the findings and confirm the fixes held - proof you can show clients, auditors and insurers.


// Why us

Real practitioners. Reports humans can read.

No scare tactics, no 200-page scanner dump. Just real, fixable risk, ranked so you know what to do Monday morning.

Certified senior partners

Testing is performed by credentialed senior testers at our vetted partner firms - named in the contract, carrying their own testing insurance, working under signed rules of engagement. We coordinate the whole thing and never dress their credentials up as ours.

Business-readable reports

A plain-English executive summary your leadership can act on, backed by the technical detail your IT team needs to fix things.

Prioritized fixes

Findings ranked by real-world risk and effort, so you spend your budget on what actually moves the needle first.

No scare tactics

We won't promise to find everything or call you "unhackable." We give you an honest read on the risk we found and how to reduce it.


// Pricing

Priced to your scope.

By quote
from ~$6,000   + HST

Small scoped engagements start from roughly $6,000 + HST. Final pricing depends on scope, targets and depth - we quote it transparently after a short scoping call. All prices in Canadian dollars, plus HST.


Authorized testing only. Full stop.

We are the authorized good guys. Every test runs under written consent, a defined scope and agreed rules of engagement - never against systems we are not cleared to touch. We handle findings confidentially, follow responsible disclosure, and hand you the keys to fix what we find.