// Methodology

Scope. Probe. Report. Retest.

A four-phase delivery model for fixed-scope application testing. Automation accelerates repeatable checks; experienced reviewers validate impact, evidence and remediation.

4 phases Fixed deliverables Clear exit criteria
PHASE 01

Scope

Before day 1

Complete the guided scope and access checklist. We confirm targets, roles, exclusions, methods and contacts, then sign the Rules of Engagement. Testing does not begin with missing inputs.

PHASE 02

Probe

Focused: days 1–5 · Full: days 1–10

Argus-assisted checks run only across the authorised surface. Manual work concentrates on authentication, authorisation, business logic and ambiguous evidence. Material findings appear in the portal.

PHASE 03

Report

Final 2–3 working days

Material findings are validated, false positives removed and evidence packaged. You receive the report, SARIF where applicable and remediation guidance. A focused handover can be scheduled if useful.

PHASE 04

Retest

Within 30 days

Website Pentest includes one retest of confirmed findings within 14 days. Web Application Pentest, Focused Validation and Full Application Pentest include one retest of reported fixes within 30 days.

Transparency

How Argus works, and what it never does

What Argus does

  • Sends HTTP requests only to authorized targets within scope
  • Records evidence including requests, responses, and reproduction steps
  • Runs the checks selected for the signed application scope
  • Produces portable evidence and SARIF where applicable
  • Runs only within the signed Rules of Engagement

What Argus never does without explicit authorization

  • Never scans hosts outside the signed scope
  • Never leaves persistent exploits or shells
  • Never exfiltrates real customer data
  • Never executes destructive payloads such as DROP TABLE or rm -rf
  • Never runs without signed Rules of Engagement on file

Human review for every engagement

Material findings recorded by Argus are reviewed by an experienced security reviewer before delivery. We verify severity, remove false positives, add remediation context and validate the quality of the evidence.

What keeps delivery predictable

Complete inputs. Controlled execution.

The delivery clock begins only after scope, authorisation and access are complete. Each phase has a defined output and exit criterion.

1
structured intake
Scope, access and constraints in one place
7–15d
pentest delivery window
Focused to full application scope
30d
included retest window
One defined retest after delivery
100%
authorised scope
Testing is blocked outside the signed engagement
Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU