Fixed, then proven fixed
Hardening Loop is a security engagement built on one loop: attack the target to find issues, fix them, then re-attack to confirm each fix actually holds. A finding closes only when its own reproduction shows the issue is gone from the patched system. The before and after evidence trail is what we hand you, not a PDF that gets filed and forgotten.
The loop
Most security reports end at a list of problems. This one ends at proof the problems are gone. The work runs as a cycle, one finding at a time and all of them together, until every issue we identified is verified closed.
We find what is actually reachable
We probe the assets in the agreed scope and record what actually answers, then rank and de-duplicate the noise into a short list of findings that matter. Each finding carries a mechanical reproduction: a check that returns PASS while the issue is present.
The fix is a separate, tracked deliverable
Each finding gets remediation guidance, and if you want us to, a fix. Findings and fixes are kept as separate artifacts with their own history, so the change and the reason for it stay legible long after the engagement.
The same check, re-run against the patch
We re-run the original reproduction against the fixed target. The finding closes only when that check demonstrates the issue is gone, which the report records as the check flipping from PASS to FAIL. Both runs are recorded with the URL, the response status we saw, and what the check looked for, so the result is auditable rather than taken on trust.
The exit condition of an engagement is plain: every finding we identified is verified remediated, each with a before and after trace recorded in the report. Anything we could not verify stays on the list as open rather than quietly counting as closed. That auditable evidence trail is the deliverable.
Three ways to start
Start small and low-commitment, or run the full loop. The engagement only ever touches assets you own and have authorized in writing.
External Attack Surface Assessment
A low-commitment on-ramp. We look at your public footprint over HTTP the way an outsider would: well-known sensitive files and paths that are reachable and should not be, the security header posture of your responses, TLS hygiene as far as response headers show it, and the technology and version details your server gives away. You get a clear, ranked list of findings with remediation steps. Findings only, no fix, easy to authorize.
Full Attack-Fix-Verify loop
The flagship. Authorized active testing of an agreed scope, remediation included, and mechanical re-verification of every fix. Each finding closes on a recorded before and after reproduction, and the engagement ends with the closure evidence trail. This tier requires a signed authorization and rules of engagement before any test runs.
Retainer
Ongoing. We re-run the loop on a cadence you set, so new surface and new findings are caught and closed on a schedule rather than once a year. Suited to teams that have been through the full loop at least once.
How this stays honest
The honest limits are the pitch, not a footnote under it.
We sell verified remediation, not a clean bill of health
We sell verified remediation of the findings we identify. We never claim a system has no issues, and we never treat an absence of findings as proof that a system is safe. What we can prove is narrow and real: the specific issues we found are closed, with both runs of the check recorded so the result can be checked independently.
Verification is mechanical, not a judgement call
The person who found and fixed an issue does not get to declare it closed. Closing is the mechanical output of re-running the original reproduction against the patched target, and the report hands you both runs together with the inputs the check used. If you want findings only and no fix from us, that removes the question entirely, and tier 1 is exactly that.
What this is not
- We test only assets you own and have authorized in writing. Scope exclusions are absolute, and anything ambiguous is treated as out of scope and left alone.
- Verified closed means one thing precisely: the specific finding's reproduction no longer works against the patched target. It is not a statement about issues we did not find or did not test for.
- A check that could not be run, or that came back inconclusive, never counts as a close. A scope denial, a transport error, a blocked request, or a check with no evaluator behind it is reported as unverified and the finding stays open.
- New code and new exposure appear over time. A closed finding stays closed for the target and configuration we tested; the retainer tier exists because surface keeps changing.
- This is an early service. The engagement method and the verification runner are built and proven against our own targets first. We would rather say that plainly than dress it up.
Scope an engagement
This is a service, so it starts with a conversation, not a download. Tell us what you want looked at and we will scope it with you: which tier fits, what is in and out of scope, and what authorization we need in writing before anything runs.