Rules of engagement
Agree written permission, systems, test boundaries and escalation contacts.
Evaluate selected security controls through a clearly authorized testing engagement.
Operating context
Define the testing boundary with the system owner before evaluating how selected weaknesses could affect the application or operation.
An owned implementation, agreed review criteria and a maintainable handover.
Agree written permission, systems, test boundaries and escalation contacts.
Assess the agreed application, API or infrastructure surfaces within those boundaries.
Present reproducible findings and prioritized corrective actions to responsible owners.
Verify agreed fixes and distinguish corrected findings from outstanding exposure.
Plan your engagement
Penetration testing assesses agreed applications, APIs or infrastructure under written authorization. Rektrs defines test boundaries, contacts and operating restrictions, then reports reproducible findings and scoped remediation or retest support.
Agree target assets, test windows, permitted techniques, exclusions and escalation contacts with the asset owner. Third-party hosted systems may need separate provider approval.
Document affected assets, evidence, business impact and prioritized corrective actions. Retesting is scoped to agreed fixes; a completed test cannot establish that a system has no remaining vulnerabilities.
Before implementation
We confirm your current systems, locations, process owners and required outputs. The proposal sets milestones, dependencies, acceptance criteria and support responsibilities for the agreed scope.