If yours isn't here, ask it on the contact form — we answer those personally.
Will you break my site? −No. We test in a window you agree, on staging where one exists, and our exploitation stops at proof. We demonstrate that something is possible; we do not destroy data, exfiltrate records, or leave anything running. If a test could plausibly disrupt service, we ask first.
Do I need to understand any of this? −No. Every finding is written twice — once in business terms for you, once in technical terms for whoever will fix it. If you have no developer, we can tell you how big a job each fix is before you go looking for one.
How long does it take? −Starter: report within five business days of the test window. Pro: seven to ten, because authenticated and business-logic testing takes longer. If we find something critical, you hear about it the same day, not at the end.
Is this a compliance audit? −No. A penetration test is an input to SOC 2, ISO 27001 and PCI DSS, not a substitute for any of them. You get a dated report with a named tester, a scope statement and a re-test record — the artifacts auditors and insurers actually ask for.
What do you need from me? −A URL, written authorization to test it (we provide the template), a contact who can be reached during the window, and test credentials if you want logged-in areas covered. If you are on a platform that requires its own permission — some hosts do — we help you request it.
What if you find nothing serious? −You still get the full report, saying so, with what we tested and how. A clean bill of health is a real, paid deliverable — we did the full work and you get the evidence that you looked. We bill for the work, not the bug count, and we would rather write that report than invent severity to justify an invoice. Every finding is reproduced by hand: if we report something you genuinely cannot reproduce, that finding is on us.
Can you guarantee we will not be hacked? −No, and we will never say we can. Testing reduces risk against the threats we could model in the time we had. New code, new dependencies and new attacker techniques all arrive after we leave. Anyone promising you "unhackable" is selling something.
Do you just resell scanner output? −No. Scanners run first because they are fast, but their output is a to-do list for a human, not a report. Everything that reaches you was reproduced by hand, and anything we could not reproduce is not in the report.
Who is actually doing the testing? −A named person, told to you before the engagement starts, who is the same person you talk to afterwards. We do not subcontract, and we do not hand your report to a junior to write up. If we ever need to bring in a second tester for a scope, you approve them by name first.
What happens to our data afterwards? −Findings and evidence are held encrypted for the length of the engagement plus the re-test window, then destroyed. We keep the scope document and the closure record. NDA on request, signed before the scoping call if you prefer.
Ask us directly Earthshaker SecurityWe find the cracks before they do. Automated and human-verified security testing for web applications.
earthshakersecurity.com · contact@earthshakersecurity.com
Earthshaker Security