The questions that come
up before a contract
Answered here so you do not have to book a call to ask.
Before you engage
Within 7 working days. That is the only response time this company publishes, and it applies to everything: scoping enquiries, office-hours requests, and vulnerability reports about our own systems. Scoping is deliberate rather than fast, and the first reply comes from whoever would run the work.
A scoping conversation. Send the systems in question, the boundary you care about, and your timeline to hello@principlebreach.com, or use the form at /contact. If what you have is one specific technical question rather than a project, /office-hours is the cheaper door and often the right one.
Some teams are better served fixing three things they already know about than commissioning a test that will find them again. That gets said during scoping rather than after an invoice. If you want a read before talking to anyone, the free assessment at /tool/red-team-readiness-checker is a reasonable starting point.
Yes. Work outside the practice, scopes too large for the budget attached to them, and engagements where testing is not the useful next step all get declined or reshaped. A referral is offered where we know someone better suited.
No. The work is remote almost end to end, and testing windows are coordinated against your team's timezone. The company is registered in India and works with organisations wherever they are.
Scope, pricing and paperwork
It depends on scope, complexity and timeline. The calculator at /tool/pentest-cost-calculator produces an indicative range from your own inputs; scoping turns that into a fixed price. Engagements are priced on the scope, not on the findings, so there is no incentive here to inflate a finding count.
Most web and API tests run for one to three weeks of testing, with a draft report days after the window closes. Larger scopes run longer, whether that is multiple systems, cloud estates, internal networks or full adversary simulation, and the timeline is fixed during scoping rather than discovered halfway through.
Always, and before scope detail changes hands. A mutual non-disclosure agreement is signed alongside the rules of engagement. Nothing found inside a client engagement is ever published, named, or referenced afterwards.
Signed rules of engagement and a letter of authorization from someone with the standing to authorize testing, plus evidence that the infrastructure owner permits it where you do not own the infrastructure yourself. Nothing is touched before both documents exist. The full list of what those documents fix is at /methodology.
No. Denial of service, destructive payloads and resource exhaustion against production are excluded by default. Where an availability risk is real it is argued from the code and configuration rather than demonstrated by taking the service down. Sensitive systems can be tested against a representative staging environment instead.
Minor shifts are absorbed. A material change is discussed before anything is done about it, with the effect on the timeline and the price stated up front. Scope is never quietly expanded and then invoiced for.
How the work runs
Six phases: scoping, authorization, pre-flight, testing, reporting, retest. Each one has an artefact, and the next phase does not start until that artefact exists. The whole process, including the evidence and data-handling standards that apply throughout, is written out at /methodology.
Neither, in the way the question usually means. The testing is run by agent swarms that enumerate, exploit and chain in parallel across the whole surface, at a breadth no human window has room for. A candidate is never reported as a candidate: it is carried through to a working exploit or it is dropped, so unverified output never reaches the report as a finding. Informational observations, which carry no exploitation claim, are the one exception and are labelled as such. A human sets the objectives, adjudicates what matters, and signs the document. The report names the accountable assessor and records the scope and methodology; the public sample does not contain an agent-by-agent inventory.
The exploitation, effectively all of it. Agent swarms enumerate, exploit and chain in parallel, which is why the coverage is wider than a person working a fixed window could reach. What stays human is the part that is judgement rather than execution: what the engagement is trying to prove, whether a reachable state is a defect or an intended behaviour, what a finding is worth against your business, and the severity argument. A person signs the report and is accountable for it. If that division does not sit right with you, say so on the scoping call rather than after.
It leaves the testing window immediately. Anything unauthenticated and serious, meaning live data exposure, authentication bypass or remote code execution, goes to the escalation contact as soon as it is confirmed, by the channel named in the rules of engagement. You act on it while testing continues.
Yes. A short written update at the start, middle and end of the window, plus immediate escalation of anything critical. Silence for three weeks followed by a PDF is the industry default; it is not this one.
Impact is demonstrated to the minimum extent that makes it unambiguous and testing then stops. Access is shown, data is not pulled. Engagement material lives on encrypted storage, is not processed through third-party services that would retain it, and is destroyed at the end of the retention period in the agreement. Test accounts, uploaded files and anything else created during testing are removed on close, with a written cleanup list handed over.
OWASP WSTG and ASVS for web and API work, MITRE ATT&CK for adversary simulation, CIS benchmarks for cloud configuration, and findings can be mapped to SOC 2, ISO 27001 or PCI DSS controls on request. Frameworks guarantee the boring coverage; the findings that matter usually come from business logic that no framework and no agent enumerate.
The report and what follows
One versioned document: executive summary, scope and rules of engagement, methodology, findings, remediation guidance, limitations, and appendices. The public sample shows this initial-report stage: all eight findings are open and it contains no retest record. When a retest is performed, its results are issued separately so the original assessment remains intact.
Yes. A complete 43-page fictional penetration testing report for Acme Corporation is publicly available to view or download at /sample-report. It shows the full deliverable without exposing client information. Real client reports remain confidential and are never published as samples or shared outside the permissions agreed with that client.
Yes. The report is yours. It is written so it can go to an auditor as-is, and a redacted copy to an enterprise prospect, without a second document being produced.
Every Critical and High finding is retested once fixes are deployed, as part of the engagement rather than as a second purchase. The fix is attacked rather than the original payload replayed, and findings close out as closed, partially closed, or open. Medium and Low are retested on request or rolled into the next engagement. The public sample is the initial assessment, so it correctly shows all eight findings as open and does not imply a retest has happened.
You still receive the full report: what was tested, what was attempted and not reached, the coverage behind that result, and an attestation that no exploitable issues were confirmed within the scope and the window. A short findings list is stated as what it is, which is evidence about a moment rather than a certificate about a system.
The CVSS v3.1 base score and vector remain visible and are not silently changed for context. Compensating controls and business context are recorded alongside that score, and remediation priority can reflect them. You review the draft for factual accuracy; where we still disagree, both positions are recorded rather than one being deleted.
About Principle Breach
An offensive security research lab and consultancy, and the trading brand of Adversary Holdings Private Limited. Two halves: scoped offensive engagements for clients, and public vulnerability research and open-source tooling that keeps the tradecraft current. The published research is at /lab and the tooling at /open-source.
No mobile client testing: iOS and Android applications are outside the practice, though the backend and its APIs are in scope. No denial-of-service work. No managed detection, no tool resale, and no compliance certification. Findings can be mapped to a framework, but whether a control satisfies your regulator is a question for your auditor and your counsel.
Yes, at /security, with machine-readable contact details at /.well-known/security.txt. It covers scope, PGP-encrypted reporting, response expectations and safe harbour for good-faith research. It is a disclosure policy rather than a paid bug bounty, and no monetary reward is offered.
Encrypt it to hello@principlebreach.com using the OpenPGP key published at /pgp-key.txt, fingerprint C3DC 3424 CBE3 0B94 59AF FBB8 9B06 8774 AE24 3BB4. The same key is shown on /contact and referenced from our security.txt.
If we are already engaged with a direct competitor of yours in a similar capacity, that is disclosed before scoping and you decide whether to proceed. Confidentiality runs both ways, so a client is never named in order to make that disclosure. The disclosure states only that a conflict exists.
Yes, once a fix is available and never at a client's expense. CVE disclosures and technical writeups are at /lab, open-source tooling at /open-source, and the same coordinated-disclosure terms we ask of researchers reporting to us are the terms we work to when reporting outward.
Questions specific to one engagement type
A question that is not here
Email it to hello@principlebreach.com and it gets a reply within 7 working days. If it turns out to be a question other people are also asking, it ends up on this page.
Bring the specific question
A scoping conversation is the fastest way to find out whether an engagement is the right spend, what it would cover, and what it would cost. If it is not, that gets said in the first reply.