Credential-led offensive security

A certified hacker whose credentials you can check yourself

Certus is a credential-led practice. Every engagement is led by a named certified hacker, so you always know who is on your systems. Moreover, you can verify each certification in a public registry before you sign anything.

Registry-verifiable credentials Authorised scope only Fixed fee, never hourly
Practitioner recordLead principal
Offensive Security Certified ProfessionalOSCP
Experienced Penetration TesterOSEP
CREST Registered TesterCRT
Web application methodologyOWASP
Execution standardPTES
Ask us for the certification number on the first call. Then check it against the OffSec credential registry yourself.
A certified hacker at a monitoring console during an authorised Certus Security assessment
Authorised assessment, live telemetry review

Credentials and standards our work is held to

OSCPpractical exam
OSEPevasion and exploit dev
CRESTaccredited testing
OWASPweb methodology
PTESexecution standard
The credentials

What a certified hacker actually holds

Certification is not decoration. Each credential below is examined, and each one sits in a registry you can search. Therefore you can confirm what we claim without taking our word for it.

Credential register, Certus practitioners
CredentialWhat it examinesHow it is awardedWhere to verify
OSCPHands-on exploitation of a live, unfamiliar networkA 24-hour practical exam, so there are no multiple-choice questionsOffSec registry
OSEPEvasion of modern defences and custom exploit developmentA 48-hour practical exam against a defended estateOffSec registry
CREST CRTProfessional competence for accredited testing workWritten and practical assessment, because CREST examines bothCREST registry
CHECKAssured testing of United Kingdom government systemsAn accredited route plus security clearanceNCSC directory
OWASPCoverage of the web application testing methodologyAn open standard, that is, a framework rather than a badgeOWASP guide

Why the exam matters more than the badge

A practical exam proves that someone can do the work under pressure. In contrast, a multiple-choice paper proves only recall. That is why we hire on practical credentials, and why we name the holder on every proposal we send.

Due diligence

How to verify a certified hacker in ten minutes

Ask any firm for the five things below. If a certified hacker cannot supply them quickly, walk away. Because these checks are public, they cost you nothing but a few minutes.

01

Get the name and the numberAsk for the practitioner who will run the test, and for the certification number they hold. A firm that answers with a company name is hiding the bench.

02

Check it in the registrySearch that number in the issuing body's own registry. OffSec and CREST both publish one, so verification takes about a minute.

03

Confirm who touches the keyboardAsk whether the person you verified is the person testing. Since juniors often inherit the work, get the answer in writing.

04

Read a redacted reportRequest a real redacted sample, not a brochure. A genuine report shows chained findings and business impact, while a scanner export shows a list.

05

Read the engagement letterThe letter should name the scope, the dates, and the authorisation. Therefore nothing begins until the system owner has signed it.

Engagements

Where a certified hacker earns the fee

Every engagement is scoped to your threat model, because a generic playbook finds generic problems. In short, these are the mandates our practitioners lead most often.

01
Web and API testing

Applications, authentication, and the interfaces behind them, tested against your real business logic.

02
Network assessment

Internal and external infrastructure, including the segmentation an intruder pivots through.

03
Cloud and identity review

Configuration, roles, and trust relationships, that is, the places where quiet privilege accumulates.

04
Red team simulation

An objective-driven simulation of a determined attacker, because people and process fail alongside technology.

05
Executive and private OPSEC

Personal footprint, home network, and device hardening for founders, executives and their families.

06
Remediation retest

A complimentary retest once you have applied the fixes, so the closure is evidenced rather than assumed.

Who we act for

Institutional first, private clients by exception

Our institutional practice is the primary focus. We act for security teams inside large organisations, on retainer and on named engagements.

For private individuals we accept a small number of bespoke mandates each year. Those are reserved for technically complex threats, and our most senior principals lead them directly. In short, it is the same standard of attention, opened to a handful of people who genuinely need it.

We do not actively market that side of the practice. Since capacity is the constraint, we also reserve the right to decline work that falls outside our technical rigour.

“We do not publish client names. References come on an NDA call.”

A logo strip proves nothing, because logos can be copied from anywhere. Instead we offer a redacted report, a named practitioner, and a reference call once the NDA is signed.

Every project is a fixed fee, agreed after we understand the threat model. Therefore the invoice never grows because a test took longer than expected.

Evidence

Proof a certified hacker should be judged on

Anyone can claim competence, so we would rather show a fragment of the work. Below is a redacted finding from an authorised engagement, presented the way it reaches the client.

Finding 04 of 17, redacted extractCritical
Client
Retail group, North America
Entry point
Exposed continuous integration runner token
Chain
Runner token to service account to vault path to domain administrator
Time to impact
41 hours from kickoff
Business impact
Full control of the production identity plane
Remediation
Three configuration changes, zero downtime, verified on retest
Redacted for publication. The full report names hosts, tokens, and reproduction steps.
Monitoring consoles in use during an authorised penetration test

A retail group, domain administrator in 41 hours

No scanner would have flagged that path, because each step looked harmless alone. Our principal chained them, proved the impact, and handed over three fixes. The client closed all three without downtime.

100%of engagements led by a named, certified principal
0client findings retained after delivery
Engagement fees

Fixed fees, scoped after we talk

from $25,000

Most engagements settle between $35,000 and $120,000, depending on scope.

We quote a fixed fee after a scoping conversation, so there is no hourly billing and no change orders. However, if your budget sits below $15,000 we are probably the wrong firm, and we will say so plainly.

Commitments

Commitments we put in writing

These are the assurances a buyer of sensitive work needs. Moreover, they belong on the page rather than buried in the terms.

  • Authorisation firstWe test only systems you own or are explicitly authorised to test.
  • Non-disclosure as standardSigned before any technical discussion, so nothing is shared first.
  • No retention of findingsYour data and results are destroyed once the project closes.
  • No subcontractingThe named practitioner does the work, because handoffs lose context.
  • Insured and clearedErrors and omissions cover, plus background-checked practitioners.
  • Encrypted throughoutEvidence and reports move over encrypted channels only.

Our minimum engagement is $25,000. A range is fine, since it helps us scope the right depth.

A senior principal replies within one business day.

Common questions

Questions about hiring a certified hacker

Is hiring a certified hacker legal?

Yes, provided the work is authorised. A certified hacker tests only systems the client owns or has written permission to test. Because authorisation is the dividing line, we require it in writing before any engagement starts.

Which certifications should a certified hacker hold?

Look for practical, examined credentials such as OSCP, OSEP, or CREST. In addition, United Kingdom government work requires the CHECK scheme. Certifications that rely on multiple-choice papers tell you far less about capability.

How do I check a certified hacker's credentials are real?

Ask for the practitioner's name and certification number, then search the issuing body's registry. OffSec and CREST both publish one, so the check takes about a minute. We supply those details on the first call.

Will you work with private individuals?

Our primary practice is institutional. However, we accept a small number of private mandates each year for founders, executives and families with a genuine threat model. A senior principal leads that work directly.

What does an engagement cost?

Engagements start at $25,000, while most settle between $35,000 and $120,000. We quote a fixed fee after a scoping conversation, so there is no hourly billing. If the budget is materially lower, we will tell you honestly.

What do I receive at the end?

You receive a report with reproducible attack chains, business risk context, and prioritised remediation. Moreover, the practitioner who ran the test briefs you directly. A complimentary retest then confirms your fixes.