Cybersecurity consultancy · San Diego, CA

We break into your systems so that no one else gets to.

Manual penetration tests, phishing simulations, and SOC 2 readiness work for small and mid-sized teams — scoped tightly, documented in plain findings, and retested until the fix holds.

Engagement type
External, internal, web app, and cloud configuration testing
Reporting
CVSS-scored findings with reproduction steps and remediation
Retest included
One verification pass on every fixed finding, no extra invoice

01 — Before you engage

The questions an informed buyer actually asks

Is this a real test or an automated scan?

Both, in that order. We run authenticated and unauthenticated scanning to establish surface area, then a human works the findings by hand — chaining misconfigurations, testing authorization logic, and validating exploitability. A scanner reports “potential”; we report “confirmed, here’s the request.”

Will testing take our production systems down?

No. We agree on rules of engagement first — testing windows, out-of-scope hosts, and rate limits. Destructive checks and denial-of-service techniques are excluded unless you explicitly authorize them in a staging environment.

Can your report satisfy our SOC 2 auditor?

Yes. Our penetration test report maps findings to the relevant Trust Services Criteria and includes an attestation letter auditors accept as evidence for CC4.1 and CC7.1. The readiness assessment produces a gap register you can hand straight to your auditor.

How long from kickoff to final report?

A focused external or web-app test typically runs 5–8 business days of testing plus 3 days for reporting. Phishing programs run over a 2–4 week window to capture realistic click behavior. We confirm exact dates in the scoping document.

What happens after we remediate?

You get one verification retest on every finding we reported, included in the engagement fee. Fixed findings move to “resolved with evidence”; anything still open stays flagged with the residual risk noted.

02 — How we work

Findings you can act on, not a PDF that sits in a drawer

Every report leads with an executive summary your board can read and closes with reproduction steps your engineers can follow. No filler CVEs padded to inflate a page count.

A security engineer working at a keyboard in low light

Hand-tested, twice-read

Every engagement is worked by the tester who scoped it and reviewed by a second set of eyes before the report ships — the same two reviewers on your findings from kickoff to sign-off.

03 — What you can count on

The terms, in writing before day one

No vague scopes and no scope creep. Here is exactly how an engagement is bounded and what you own at the end.

01

Fixed scope, fixed fee

Hosts, applications, and testing windows are agreed in a signed scoping document. If new surface appears mid-engagement, we quote it separately — your original number holds.

02

You own the report

Findings, evidence, and the raw data are yours to share with auditors, insurers, or customers. We keep an encrypted copy for 12 months, then it’s destroyed.

03

NDA both directions

We sign your NDA or supply ours before any credentials change hands. Test data is handled under least-privilege access and wiped from our systems at close-out.

04

Retest built in

One verification pass on every reported finding is part of the fee — not an upsell. You leave with proof the holes are actually closed.

04 — The engagement

From kickoff to a clean retest

1

Scoping call

A 45-minute session to map your assets, agree rules of engagement, and set testing windows. You get a fixed-fee scoping document before anyone touches a system.

2

Testing window

Reconnaissance, scanning, and hands-on exploitation across the agreed targets. We flag critical findings the moment we confirm them — you don’t wait for the report to learn you’re exposed.

3

Reporting

A CVSS-scored report with an executive summary, reproduction steps, and prioritized remediation — plus an auditor-ready attestation letter where SOC 2 is in play.

4

Verification retest

Once you’ve remediated, we re-test each finding and mark it resolved with evidence. Residual risk on anything still open is documented in plain language.

05 — Request a scope

Tell us your surface, get a scoped quote

Send a few details about what you run and what you’re trying to prove. We reply within one business day with a fixed-fee scoping proposal — no sales sequence, no “discovery funnel.”

  • Weekday replies within one business day
  • NDA signed before any technical detail
  • Serving San Diego and remote engagements across the U.S.

Or email hello@kassandrasecurity.com directly.

06 — Engagements & pricing

Three ways to start

Starting points for typical small and mid-sized scopes. Final fees are set in the scoping document once we’ve mapped your surface.

Phishing Program

Test the human layer

From $1,850per campaign wave
  • Tailored pretext & lookalike domains
  • Click, submit & report metrics by team
  • Just-in-time training landing page
Scope a campaign
Most requested

Penetration Test

External, web app & cloud

From $6,500per engagement
  • Manual exploitation, not scan output
  • CVSS-scored report + attestation letter
  • Verification retest included
Request a scope

SOC 2 Readiness

Get audit-ready first

$9,400fixed assessment
  • Gap register mapped to Trust Criteria
  • Policy & control review
  • Prioritized remediation roadmap
Start readiness

07 — Reach the desk

Details, on the record

Office

10517 Caminito Pollo
San Diego, CA 92126

Hours

Weekdays 10am–5pm

Coverage

San Diego on-site · remote across the U.S.