Skip to content
Services
How it works Scope & safety Findings Review desk Blog Write to us
HomeServicesWork with Zaaf
Work with Zaaf

Tell us what is changing.
We’ll help define the test.

Start with the system, the decision you need to make and your timeline. We will discuss technical fit and define a written scope before testing begins.

INSIDE THE ASSESSMENT
A clear beginning. An agreed scope.A brief leads to a scoping discussion and written engagement terms. Contact does not authorize testing.Your briefSystem, priorities, timingScope discussionFit, access and boundariesAgreementBefore testingDEFINED TOGETHER
A clear beginning. An agreed scope.
BriefScopeAgreement
01 / Choose the engagement

The right shape of work.
For the decision ahead.

These are proposed engagement shapes, subject to technical fit and availability. Pricing is agreed after scoping.

AssetsScopeReportA DEFINED QUESTION
SCOPED ASSESSMENT

Focus on a product
or a trust boundary.

You need a bounded assessment of selected systems and workflows.

A useful starting point
The application or integration you want assessed and the reason it matters now.
What we define
Assets, roles, permitted actions, reporting needs and exclusions.
What to expect
A proposal based on technical fit and the agreed depth of the work.
ChangeReviewReleaseA MEANINGFUL CHANGE
RELEASE ASSESSMENT

Bring the change
into the testing scope.

You are preparing a sensitive workflow, integration or infrastructure change.

A useful starting point
What changed, the release dependencies and the decision date.
What we define
Relevant components, environments and access available before that date.
What to expect
Timing confirmed during scoping—not an automatic promise to meet every deadline.
ReviewFixRetestFOLLOW-THROUGH BY AGREEMENT
RECURRING REVIEW

Revisit what changes.
Check selected fixes.

You want proposed recurring reviews around changes and remediation.

A useful starting point
The cadence of releases and the types of changes that warrant review.
What we define
Frequency, selection of work, reporting and retest terms.
What to expect
An explicitly scoped engagement, not implied continuous monitoring or unlimited coverage.
02 / Prepare the conversation

A short brief.
A more useful first call.

What to share in an initial inquiry
IncludeUseful contextPlease avoid
System & surfaceUseful contextWeb/API, cloud or Web3; a short product and architecture description.Please avoidCredentials, private keys or unrestricted access links.
Reason nowUseful contextThe release, integration, customer request or security concern driving the work.Please avoidAssuming that contacting us authorizes testing.
Proposed scopeUseful contextApproximate assets, relevant roles and available test environment.Please avoidUnrelated third-party targets or assets you cannot authorize.
TimelineUseful contextThe target date and any external dependencies.Please avoidPromising a delivery date to your buyer before we confirm availability.
RequirementsUseful contextYour technical contact and specific reporting or contractual needs.Please avoidSensitive findings or customer data in the initial message.
03 / Before testing starts

A conversation first.
An agreement before access.

The initial discussion establishes fit. Access and testing follow the agreed engagement, not the initial inquiry.

  1. 01

    Discuss the need

    Clarify the systems, decision, constraints and technical fit.

    INITIAL CONVERSATION
  2. 02

    Confirm the scope

    Agree on authorization, access, actions, timing, deliverables and commercial terms.

    WRITTEN ENGAGEMENT
  3. 03

    Coordinate kickoff

    Establish contacts, permitted environments and escalation arrangements.

    CONTROLLED START

A booking or email does not start a security assessment or authorize automated testing.

04 / What you receive

A proposal you can evaluate.
Before the work begins.

The scope should be understandable to the person authorizing the work and to the engineers supporting it.

Send your scope summary ↗
ILLUSTRATIVE STRUCTURE · NOT A CUSTOMER REPORT
ENGAGEMENT OUTPUT

Context. Evidence.
A useful next step.

01

Scope & exclusions

Named systems and workflows, relevant environments and known limitations.

02

Access & responsibilities

Required accounts, customer inputs and permitted operations.

03

Delivery & timing

Proposed deliverables and agreed scheduling expectations.

04

Commercial & follow-up terms

Pricing, retesting and any additional requirements confirmed for the engagement.

05 / Before we start

Practical questions.
Clear expectations.

Bring your technical constraints and buyer requirements to the scoping conversation.

How much does an assessment cost?

Price depends on scope, complexity, access, reporting and follow-up needs. We quote after discussing the engagement; no legacy prices apply to these options.

How long does it take?

Timing depends on the agreed work and availability. Share your target date so we can establish a realistic proposal before you make external commitments.

Can we begin with a small scope?

A focused assessment can be discussed, subject to technical fit. Its conclusions apply only to the agreed scope.

What if we need an NDA or particular data terms?

Share those requirements before sending sensitive material or granting access. Specific commitments need to be confirmed rather than assumed.

Does booking a call trigger testing?

No. Booking is for a conversation. Testing requires an agreed engagement and authorization.

Do you offer physical-device testing?

Not currently. Physical-device security testing is in development and remains a roadmap item.

LET’S DEFINE YOUR ENGAGEMENT

Bring us your scope.
We’ll discuss the next step.

Share your system, priorities and target date.
Please do not include credentials or sensitive findings.