Security Principles

Not rules to follow.
Principles to test against.

Every engagement we run is shaped by the same four principles. They are not a slogan on a slide — they are the standard we hold ourselves to on every assessment, every finding, every report.

EvidenceOnlyNo finding without proof.
0TemplatesNo copy-paste checklists.
ManualValidationEvery result, human-checked.
ContextFirstRisk framed for your business.

The Four Principles

What guides
every engagement.

01VERIFY

Assume nothing is secure until it is proven.

Every system, control and claim starts as unverified. We do not treat a policy document, a compliance badge or a vendor's word as evidence. We test until we have proof — or until the gap is exposed.

02EVIDENCE

Every finding needs evidence, not opinion.

We do not report a risk we cannot demonstrate. If we say something is exploitable, we show how. If we say something is low priority, we explain the reasoning — not just a severity label pulled from a scanner.

03RISK

Risk before compliance.

Passing an audit and being secure are not the same thing. We prioritise the risks that could actually cause harm to your organisation, even when they sit outside whatever framework you are being measured against.

04DEPTH

Depth over checklists.

A checklist tells you what was looked at. It does not tell you what was understood. Our assessments go as deep as the environment requires, not as deep as a template allows.

In Practice

Common practice vs
our principles.

Findings

Reported based on scanner severity, regardless of real exploitability in your environment.

Reported only once manually validated and shown to be genuinely exploitable.

Priority

Ranked by a generic CVSS score, disconnected from your architecture and operations.

Ranked by real impact to your specific systems, data and threat model.

Compliance

Treated as the end goal of the engagement — pass the audit, close the ticket.

Treated as a byproduct of doing the security work properly, not the definition of it.

Depth

Bounded by whatever a checklist or template defines as in scope.

Extended as far as the environment and threat model demand — no artificial limits.

What This Means

Principles, not
good intentions.

These principles are only useful if they change what actually shows up in your report. Here is what that looks like.

This is not…
  • A generic checklist run against your environment.
  • Findings copy-pasted from an automated scanner report.
  • Severity ratings without context for your business.
  • A compliance stamp with no real testing behind it.
This is…
  • Manual validation of every finding we report.
  • Risk explained in terms of impact to your organisation.
  • Clear reasoning behind every priority we assign.
  • Recommendations built for your architecture, not a template.

Common Questions

Things people
usually ask.

No. They shape how every engagement is scoped, tested and reported. If we cannot apply a principle to a piece of work, we say so rather than pretend otherwise.

No. We map findings to the frameworks you need. We just don't let the framework's checklist define the limits of the assessment.

We say so directly. An unclear result is reported as unclear, with what it would take to confirm it — never rounded up to a definitive finding.

Manual validation takes longer than an automated report. We are upfront about timelines from the start, because we will not skip verification to hit a deadline.

Ready to be tested?

See what these principles
find in your environment.

If you want an assessment built on evidence rather than assumption — and a report you can actually act on — we are ready to start.