Tell us about your environment. We respond within 4 hours with a senior operator and a scoped free attack-surface assessment, not a sales call.
Our security team will contact you within 4 hours to schedule your free assessment.
A scoped engagement delivered in five business days. Not a sales call, not a generic scan. A real first look from a senior operator.
All internet-facing assets tied to your primary domain enumerated and risk-scored.
Cross-reference of your email domain against active breach corpora and stealer logs.
Prioritised exposures with remediation guidance, in language your engineers can act on.
Walkthrough of findings with the senior operator who ran the assessment, no handoff.
No commitment. No follow-up sales cadence. If we don't surface anything worth your time, we tell you and close the file.
We're building Dark Force in public, hand-picking our first cohort of clients. These engagements set the tone, the methodology, and the long-term roster. Founding cohort clients get a permanent advisory line to a founder, priority slots ahead of waitlist, and direct input into the services we build next.
Cohort Status
3 / 8
priority slots remaining
Closes at full allocation. We expect this within the current quarter based on inbound volume.
Yes. A mutual NDA is executed before scoping begins. Our standard template is provided on first contact, and we accept yours if you prefer.
Scoping call within 24 to 48 hours. Most engagements kick off within one to two weeks. Incident response is a separate track with an under-four-hour senior operator response from initial call.
External or web pentest: 2 to 3 weeks. Internal pentest: 3 to 4 weeks. Full red team: 4 to 8 weeks. Dark web monitoring and credential leak protection are ongoing subscriptions. EDR assessments are scoped per fleet size.
All engagement data is encrypted at rest in EU-region storage by default. Standard retention is 90 days post-engagement followed by cryptographic destruction. Alternative jurisdictions and shorter retention windows are available on request.
Every operator clears a background verification before client work. Certifications, CVE disclosure history, and prior employer references are documented and shared under NDA during scoping.
Yes. Professional indemnity and cyber liability coverage is in force for every engagement. Certificates of insurance and coverage limits are provided at contract execution.
Large consultancies often send senior names to the pitch and junior consultants to the engagement. We are the opposite. The operator who scopes your engagement is the operator who runs it, writes the report, and stays on the line for retests.