Authorized Offensive Security
We test your environment the way a real attacker would — under a signed engagement, on a standards-based methodology. No vague PDF of findings. A written result that says exactly what held, what didn’t, and what was proven.
Why SiegePoint
Most testing ends in a PDF full of findings and no agreement on what any of it meant. SiegePoint is built the opposite way: every engagement begins with a signed authorization and rules of engagement, runs on a repeatable technique taxonomy, and ends against a contractual acceptance model — our Surrender Levels — so you know precisely how deep we got, what held, and what has to change.
Nothing happens without a signed authorization-to-test letter and agreed rules of engagement. Scope, targets, windows, and escalation paths are defined before the first packet.
Engagements follow a documented, standards-aligned taxonomy of techniques with a built-in guardrail layer — reproducible, reviewable, and safe to run against production.
The Surrender-Levels model turns "we poked around" into a written statement of what a successful test achieved, so results are unambiguous to engineers, executives, and auditors alike.
Services
Full-scope adversary simulation against the surfaces attackers actually use.
Detection validation — not "are you vulnerable," but "would you even see it?"
Methodology
SiegePoint doesn't improvise. Engagements run on a documented architecture — a technique taxonomy, an execution model, and a safety layer that keeps authorized testing from ever becoming an actual incident. The full methodology and the acceptance model are published for clients and partners to review before a single test begins.
The Acceptance Model
Every attack surface maps onto the same five rungs, so acceptance is defined in one consistent language across the whole engagement. Each in-scope vector is dialed to a level in the Statement of Work — and that single number sets two things at once: the success bar (how far we must get to prove a control failed) and the stop line (how far we are authorized to go). This is the model in brief; the published document defines each rung and its evidence requirements in full.
The attack surface is exposed and in reach — the door is findable, nothing tried yet.
Would-surrender proven, not taken. A weakness is demonstrably exploitable, or a person engages (clicks the lure, answers the pretext) — proof compromise would occur, with nothing actually taken.
Disclosure & access obtained. The secret or access is actually in hand — credential captured, OTP disclosed, foothold established, data readable — held but not yet used.
A safely nefarious action inside an agreed, reversible blast radius — demonstrating the surrender had real consequence. Requires a named approver and explicit written authorization.
The crown-jewel flag is captured — the pre-defined target asset reached, full chained business impact. The deepest authorized surrender, and the strongest consent requirement.
The rung at which the test authenticates as successful — below it the control held; at or beyond it, the control failed and a finding is raised. Objective, not editorial.
The maximum rung SiegePoint is permitted to reach — always at or above the pass threshold, and a mandatory stop line whatever else may be possible. The client dials their own risk.
How an Engagement Works
Define targets, objectives, windows, and the target Surrender Level together.
Signed authorization-to-test letter and rules of engagement — your get-out-of-jail paperwork.
Testing runs on the documented methodology, fully scoped and logged, guardrails on.
Findings by severity and CVSS, evidence of the level reached, and a prioritized fix path.
Retest verifies the fixes held — the loop closes, not just the ticket.
For MSSPs & Consultancies
SiegePoint is built white-label first. Firms that need a credible, standards-based offensive and detection-validation capability — without building the methodology, tooling, and reporting from scratch — can run SiegePoint under their own brand, with our engine and guardrails underneath.
Talk about partnering »Every SiegePoint engagement starts with a conversation about scope and a signed authorization. Tell us what you want tested and how deep you want us to go.