Axesec

Approach

Methodology and reporting.

Every engagement follows the same structure, whether it lasts a week or a quarter. You know who is testing, what is in scope and how to reach them at any time.

Engagement lifecycle

  1. Scoping

    A call with the engineer who will lead the work. We agree on objectives, targets, depth, test accounts and timing, then send a fixed-scope statement of work.

  2. Rules of engagement

    Written authorization, in-scope and out-of-scope assets, testing windows, emergency contacts and stop conditions. Testing does not begin until the rules of engagement are signed.

  3. Testing

    Manual testing by senior engineers. Critical and high-severity findings are reported the day they are confirmed. You get status updates on a cadence you choose, and a shared channel to the team.

  4. Reporting

    An executive summary for leadership and a technical report for engineers, followed by a readout with each audience.

  5. Remediation support and retest

    We answer your engineers' questions during remediation, retest every finding, and issue an updated report and attestation letter.

Standards

Frameworks we test against.

MITRE ATT&CK
Red and purple team planning, technique coverage and reporting.
OWASP ASVS, WSTG, MASVS
Web, API and mobile application testing coverage.
OWASP Top 10 for LLM Applications, MITRE ATLAS
AI, LLM and agent assessments.
PTES, NIST SP 800-115
Network and infrastructure penetration testing.
CVSS
Severity scoring, always paired with impact in your business context.

The report

What the report contains.

  • Executive summary: overall risk, key findings and recommendations in plain language.
  • Scope, methodology and testing timeline.
  • Attack narrative showing how individual findings chain into real impact.
  • Findings with severity, CVSS vector, affected assets, evidence and reproduction steps.
  • Remediation guidance specific to your stack.
  • Retest results and an attestation letter for customers and auditors.

Confidentiality

How we handle your data.

  • All work is performed under NDA, a signed statement of work and written authorization.
  • Client data is encrypted in transit and at rest. We collect only what is needed to prove a finding.
  • Engagement data is deleted on a retention schedule agreed in advance.
  • Reports and credentials are exchanged over encrypted channels only.
  • We do not disclose client names without written permission.

Contact

Ready to scope an engagement?

Run scope below to start a request, or use the contact form. An engineer will reply, usually within one business day.

cat contact.txt

email hello@axesec.com

security security@axesec.com

pgp key available on request

location New York, NY