How It Works
A transparent, authorization-first approach to security assessments. From request to ongoing monitoring, we partner with you every step of the way.
Request an Assessment
Begin with a direct scope conversation.
- Provide basic organizational and contact information
- Describe the domains, applications, or infrastructure to be assessed
- Confirm you are authorized to discuss the proposed targets
- Receive direct follow-up to begin scope review
Submit Targets for Assessment
Provide the targets you want assessed and confirm authorization.
- Submit target domains, IP addresses, or fully qualified domain names
- Provide an estimated target count
- Confirm you hold authority to request security assessments against specified targets
- Receive confirmation of submission
Scope Validation & Ownership Verification
We review your submission to identify in-scope targets and verify ownership.
- We perform discovery to identify all infrastructure associated with submitted targets
- You receive a scope validation review identifying: submitted targets, additional candidate targets, informational infrastructure, rejected/out-of-scope candidates
- You review the proposed scope and approve, reject, request manual review, or confirm final authorized scope
- If needed, we perform ownership verification (DNS TXT record or file upload)
Authorization & Assessment Approval
Sign the Letter of Authorization (LOA) to formally authorize the assessment.
- Review and approve the finalized scope
- Sign the Letter of Authorization electronically
- Confirm your relationship to the targets and legal authority
- LOA is countersigned by SunTzu Security Labs
Proposal & Assessment Preparation
Review a written proposal and schedule the authorized assessment.
- Receive a quote based on the approved scope and monitoring cadence
- Approve commercial terms for a one-time assessment or continuous monitoring
- Schedule your assessment start date and preferred scan window
- Receive confirmation of scheduled assessment
Assessment Execution
Our platform conducts comprehensive security assessments against approved targets.
- Assessments are executed during your preferred scan window
- External attack surface analysis
- Vulnerability identification and classification
- Risk scoring based on exposure, exploitability, and business impact
- All findings are documented and prepared for reporting
Reporting & Risk Visibility
Access detailed reports with executive summaries, findings, and remediation guidance.
- Executive summary with security posture overview
- Technical findings with risk prioritization
- Step-by-step remediation guidance
- Compliance control annotations (if applicable)
- Historical trending and comparison data (for recurring assessments)
Continuous Improvement
Track your security posture over time with recurring assessments and trend analysis.
- Scheduled recurring assessments (for continuous monitoring plans)
- Track remediation progress
- Compare current findings to historical data
- Receive alerts for newly identified critical risks
- Measure security improvements over time
Security Assessments Should Be Transparent
Customers maintain visibility into scope, authorization status, progress, and report availability throughout the entire engagement lifecycle.
Clear Visibility
You always know what we're scanning, when, and why. No surprises.
Proper Authorization
We never scan without proper authorization. Your legal protection is our priority.
Progress Tracking
Receive clear status updates, report availability notices, and remediation follow-up.