Every Engagement Is Scoped. Not Quoted.
We price what we actually have to test, not a line item from a template. One scoping call, then a proposal built around your environment and the risk you care about closing.
Entry Floor
Single-application engagements typically start around $12k. Final scope is fixed in the proposal, never before. The number moves with the work, not with how much we think you'll pay.
100% manually validated findings·Custom proposal within 48 hours
Pricing Tiers
REF · OIU-PRICING-2025Pick a Service. Scope a Tier.
Pick a service to see how its tiers build on one another. The tier is a starting point; your final scope and number come out of the call.
Pricing Tiers
Starter
Single-asset penetration testing by senior operators.
- Web app, mobile app, or up to 50 network IPs
- Manual testing by senior operators
- Report with CVSS scoring + executive summary
- Actionable remediation guidance
- 2 to 3 week delivery
- Remediation verification retest
Professional
Continuous testing and retesting for maturing security programs.
- Everything in Starter
- Continuous testing cadence
- Dedicated Slack channel for real-time comms
- Quarterly security reviews and trend analysis
- Same operator across quarters. Context compounds.
- Priority scheduling and expedited delivery
Enterprise
Full offensive security program with dedicated account team.
- Everything in Professional
- Multi-asset and multi-environment coverage
- Dedicated account team and CISO-level reporting
- Custom testing methodologies
- Threat intelligence briefings
- CISO-level program review every twelve months, with the named operator in the room.
Included · Every Engagement
The Price Is Scoped. The Standard Is Fixed.
The number on the proposal moves with the work. What it buys does not. Whether you spend $12k on a single application or run a full program, the same four commitments are written into the SOW, and none of them is a line item you pay extra for: one senior operator start to finish, unlimited untimed retest, artifact destruction in 30 days with written attestation, and no platform or seat fee.
That is what “scoped, not quoted” buys you: the proposal fixes the number and the standard at once. Each commitment is spelled out in full under The Standard.
File · Scoping FAQ
Frequently Asked Questions
The answers a quote PDF will not give you.
Q1 How is this different from a Nessus or Qualys scan?
A scan runs automated checks against known CVEs. A pentest is human operators chaining low-severity findings into critical attack paths, exploiting business logic, and demonstrating real impact on your specific environment. Scanners report noise. We report what matters and what to do about it.
Q2 Will junior testers do the actual work?
No. Every engagement is staffed by senior operators with a decade or more of offensive security experience. The operator who scopes your engagement is the operator who delivers it and presents the readout. No rotating juniors, no offshore handoffs.
Q3 What happens if you find nothing critical?
That is a valid outcome and we say so plainly. You get a report documenting the methodology, the scope tested, the techniques attempted, and a defensible attestation of effort. You also get a roadmap for what to test next so the next engagement goes deeper, not wider.
Q4 Can you sign our MSA, DPA, and BAA?
Yes. We routinely sign enterprise master service agreements, data processing addenda, and business associate agreements. We carry E&O and cyber liability insurance. Procurement and legal documentation is sent within 48 hours of request.
Q5 What is your SLA for critical findings discovered mid-engagement?
Critical findings are reported within 24 hours of validation. We do not wait for the final report to surface real risk. You get a written brief, a debrief call with the operator, and immediate remediation guidance.
Q6 Are compliance-ready reports and attestation letters included?
Yes. Every engagement includes a full technical report with executive summary, CVSS scoring, attack narratives, remediation guidance, and a compliance attestation letter mapped to PCI DSS, SOC 2, ISO 27001, HIPAA, CMMC, NIST 800-53, or FedRAMP. No additional cost.
Q7 What does onboarding look like?
Schedule a 30-minute scoping call. We diagnose your environment, objectives, and compliance pressure. You receive a custom proposal within 48 hours. Once signed, we kick off within two weeks. No generic quotes, no commodity packages.
Q8 What counts as an 'asset' for scoping?
An asset is a distinct target: a web application, mobile app, API, or network range (up to 50 IPs per range). Multi-page web apps count as one asset. Separate applications or distinct network segments count separately. We clarify during scoping so there are no surprises.
Talk to an Operator
See What Your Quote Should Cover
Send the twelve-question checklist to your shortlist. The answers tell you everything a quote does not.