Everycontrolclaimsitworks.
Put it à l'épreuve.
We start from your risks, work out the protection that must exist, and attack every control that claims to provide it with your own records. Then we try to break our own conclusions before you rely on them.
Nine steps. From your register to the retest.
The same deterministic loop for every scenario, every control family and every retest. Code executes, an agent and a reviewer attack the answer, a person releases.
- 00risk01 reconin your register as it is, plus what we may add: breaches at comparable companies, breaches involving your vendors, the data you hold, your incident recordsoutthe top risks, high or critical, each with its signals and their provenance[!] a missing or under-rated risk comes back to you as an evidence-backed challenge; you own the register
- 01scenario01 reconin one riskouta handful of concrete paths, attack and failure alike, each with the protection it requires
- 02claim01 reconin the required protectionoutthe controls that claim to provide it, listed in your framework or not, with their assumptions marked as positions[!] each control is judged by its capability, coverage and reliability against the path, never averaged into a score
- 03populate02 huntin positions, sources, periodoutexpected against obtained population, exclusions, source health[!] a sample supports only its own inference; one application does not establish all applications
- 04procedure02 huntin one positionouta versioned procedure: payload, assertion, oracle, limits, and the exact authority to run it
- 05run02 huntin procedure, population, periodoutone result per position: held, broke, open or not run, with its confidence[!] same inputs, same bytes; any change is a new revision, never an edit
- 06challenge03 challengein results and the reasoning behind themoutrelease, or a hold that blocks release until evidence or a named reviewer resolves it[!] an adversarial agent objects, a named reviewer decides; four failures block our release whatever your controls did[-] an unsupported favourable conclusion[-] an unsupported adverse conclusion[-] a missed known material failure[-] missing evidence treated as a pass
- 07debrief04 debriefin released and held results across the scopeoutone assessment, several views: team, risk owners, board, engineering, auditor[!] not run is printed first; held is a result, not an absence
- 08retest04 debriefin your fix, a new periodouta new run linked to its parent; the original finding stays[!] re-enter the loop where the fact changed
One claim. Four positions. Attacked one at a time.
The claim came from a scenario, the scenario from a risk in the register. Each assumption inside the claim is a position; each position gets its own payload from your records, its own status and its own confidence. Keep scrolling to run them.
- payload
- idp/auth-events · 06-01→06-30
- assert
- local_login_events == 0 → 41 sso+mfa · 0 local
- payload
- idp/config-snapshot@06-14 · 7c1e…
- assert
- local_login == false → true
- payload
- idp/config-snapshot@06-14
- assert
- mfa_required == all → mfa on all 41
- payload
- exception-approvals
- assert
- approvals delivered → not delivered
A green tick is a claim.
Platforms start from a control list.
We start from your risks and write down what protection must exist. Then we look for it.
Evidence is collected, not attacked.
Every assumption in a claim gets a payload from your own records and a fixed, inspectable procedure.
Nobody prints confidence.
Certain, firm or tentative on every result. Uncertainty is a finding, not a footnote.
Nobody attacks their own answer.
An adversarial agent objects, a named reviewer decides, and a hold blocks release. Review never turns broke into held, and held is a result we are glad to print.
Not the auditor. The hunt before the audit.
Your team commissions it and acts on it. Your auditor reads our trace, reperforms what they want, and signs their own report.
Open a target. See the whole hunt.
Deep assurance. Boring audits.
Fixed fee · full SOC 2 scope · one retest · you remediate · your auditor signs