Standard On Every Engagement

Unlimited Remediation Validation.

Re-test as fixes land. No time cap. No per-finding charge. The engagement is not done until the findings are closed.

By Bailey Besheer ·

File · What Bailey

What Bailey said

Operator Note OPR · STANDARD-OF-WORK
“Unlimited remediation validation is standard on every engagement, the way I'd want to be treated as a buyer. Clients work through findings at their own pace and re-test with us as fixes land, with no time cap and no per-finding charge. We've kept retest engagements active for over a year without additional billing.”
Bailey Besheer, Managing Director of Cybersecurity Services

File · How it

How it works mechanically

  • [01] Engagement closes, retest opens. When the final report is delivered, your retest engagement is opened automatically. There is nothing to sign and nothing to procure.
  • [02] You set the cadence. Some clients re-test in batches every two weeks. Others re-test individual findings the same day a fix lands. We work to your rhythm, not ours.
  • [03] No per-finding charge. The retest covers every finding in the original report, regardless of severity or count. If we found it, we retest it.
  • [04] No time cap. Complex fixes take time, and a refactor that lands six months out still gets validated under the original engagement. We do not penalize you for fixing things properly.
  • [05] Updated attestation on every retest. Each retest produces a written delta document your auditors and customers can rely on.

File · Why this

Why this is structurally different

Most vendors charge per retest or cap retests at 30 days. Per-retest fees turn remediation into a billable event, which puts the vendor's incentive to invoice in direct conflict with your incentive to close findings cleanly.

Our position is simpler. The engagement is not finished until the findings are closed, so charging twice for the same engagement never made sense to us.

File · FAQ

Frequently Asked Questions

Q1 Does unlimited retest apply to red team engagements?

Yes. Every offensive engagement (pentest, red team, social engineering, product security) includes unlimited retest.

Q2 Is there a cap on the number of retests per finding?

No. If a fix needs three rounds to land cleanly, we retest three times. The retest is on us.

Q3 What if the original finding is no longer reproducible after a refactor?

We mark it closed and note the refactor in the delta document. We do not invent reasons to keep the finding open.

Q4 How long can a retest engagement stay open?

As long as it takes to close the findings. There is no time cap, and we have carried retests well past a year when a fix needed a real refactor.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.