Penetration Testing · Piqua, Ohio
Held To
The Light.
We test small and mid-sized systems the way a real attacker would, then hand you the findings in plain language — plus a route to SOC 2 or HIPAA. Priced per engagement, no retainer to sign.
01 · What We Run
Four Engagements
Most companies find us right before a customer's security review, an audit deadline, or a launch. We come in, do the work, and leave you with a report an engineer can act on and a summary a board can read. Each engagement below is fixed-scope and fixed-fee.
Penetration Test
External and internal testing of your web app, API, and network. Manual exploitation, not just a scan — with a retest included once you've patched.
Security Audit
A review of your cloud config, access controls, and code review practices, ranked by what an attacker would reach first. Good before you scale headcount.
SOC 2 Readiness
Gap assessment against the Trust Services Criteria, a mapped list of what to fix, and the evidence you'll need before your Type I or Type II.
HIPAA Readiness
Risk analysis and safeguards review for practices and health-tech handling PHI, written to survive an actual OCR question, not just to tick a box.
02 · How We Work
“A report that sits in a drawer never fixed anything. We write findings the engineer on call at 2am can actually follow.”Lantern — the whole reason we keep it plain
03 · Who Sits Across The Table
Built For Smaller Teams
SaaS & Startups
Passing the security review
Your biggest prospect sent a 200-row questionnaire. We test what matters and give you the SOC 2 path to answer it honestly.
Health & Clinics
PHI without the panic
Small practices and health-tech teams get a HIPAA risk analysis that maps to real safeguards, not a generic checklist.
Fintech & Payments
Where money moves
API abuse, broken authorization, and access sprawl are where we spend our time — because that's where the loss is.
MSPs & Agencies
Testing you can hand a client
White-label-friendly reports for teams that manage other people's infrastructure and need a name on the assessment.
Regional Business
Ohio & the Miami Valley
Based on S Wayne St in Piqua. Happy to work remote, and happy to drive to you when the engagement calls for it.
04 · Start The Conversation
Request A Scope
Tell us what you're running and what's driving the timeline. We'll reply within one business day with a scope, a fee, and a start date — no sales sequence.
05 · Before You Book
The report is the product
You get an engineer-grade findings document, a remediation-ranked action list, and an executive summary. Then a retest once you've fixed things — included, not billed again.
Request a scope
06 · Working Together
Fixed scope, fixed fee
Every engagement is quoted up front against a written scope. If the work grows, we agree on it before we touch it — you never open a surprise invoice.
Call (937) 980-9035
07 · Reasonable Questions
Before You Commit
Will a test take our systems down? +
No. We agree on a window and rules of engagement in writing before we start, avoid destructive tests on production, and stay reachable throughout. If something looks fragile, we flag it rather than break it.
We're small — is a pen test overkill? +
Usually the opposite. Smaller teams get one questionnaire, one breach, or one failed audit and it hurts more. A scoped test on the two or three systems that matter is far cheaper than the alternative.
How long does an engagement take? +
A focused pen test or audit is typically one to two weeks of testing plus a few days to write it up. SOC 2 and HIPAA readiness run longer depending on how much evidence already exists. You get a start and delivery date in the quote.
Do you do the SOC 2 audit itself? +
No — that has to come from a licensed CPA firm, and keeping those separate is the point. We get you ready: the gap assessment, the fixes, and the evidence, so the audit is a formality instead of a scramble.
What do you need from us to start? +
Scope (what to test), access or credentials for the agreed targets, a technical contact, and a signed authorization. We send a short checklist after the scoping call so nothing stalls.