A certified hacker whose credentials you can check yourself
Certus is a credential-led practice. Every engagement is led by a named certified hacker, so you always know who is on your systems. Moreover, you can verify each certification in a public registry before you sign anything.
Credentials and standards our work is held to
What a certified hacker actually holds
Certification is not decoration. Each credential below is examined, and each one sits in a registry you can search. Therefore you can confirm what we claim without taking our word for it.
| Credential | What it examines | How it is awarded | Where to verify |
|---|---|---|---|
| OSCP | Hands-on exploitation of a live, unfamiliar network | A 24-hour practical exam, so there are no multiple-choice questions | OffSec registry |
| OSEP | Evasion of modern defences and custom exploit development | A 48-hour practical exam against a defended estate | OffSec registry |
| CREST CRT | Professional competence for accredited testing work | Written and practical assessment, because CREST examines both | CREST registry |
| CHECK | Assured testing of United Kingdom government systems | An accredited route plus security clearance | NCSC directory |
| OWASP | Coverage of the web application testing methodology | An open standard, that is, a framework rather than a badge | OWASP guide |
Why the exam matters more than the badge
A practical exam proves that someone can do the work under pressure. In contrast, a multiple-choice paper proves only recall. That is why we hire on practical credentials, and why we name the holder on every proposal we send.
How to verify a certified hacker in ten minutes
Ask any firm for the five things below. If a certified hacker cannot supply them quickly, walk away. Because these checks are public, they cost you nothing but a few minutes.
Get the name and the numberAsk for the practitioner who will run the test, and for the certification number they hold. A firm that answers with a company name is hiding the bench.
Check it in the registrySearch that number in the issuing body's own registry. OffSec and CREST both publish one, so verification takes about a minute.
Confirm who touches the keyboardAsk whether the person you verified is the person testing. Since juniors often inherit the work, get the answer in writing.
Read a redacted reportRequest a real redacted sample, not a brochure. A genuine report shows chained findings and business impact, while a scanner export shows a list.
Read the engagement letterThe letter should name the scope, the dates, and the authorisation. Therefore nothing begins until the system owner has signed it.
Where a certified hacker earns the fee
Every engagement is scoped to your threat model, because a generic playbook finds generic problems. In short, these are the mandates our practitioners lead most often.
Applications, authentication, and the interfaces behind them, tested against your real business logic.
Internal and external infrastructure, including the segmentation an intruder pivots through.
Configuration, roles, and trust relationships, that is, the places where quiet privilege accumulates.
An objective-driven simulation of a determined attacker, because people and process fail alongside technology.
Personal footprint, home network, and device hardening for founders, executives and their families.
A complimentary retest once you have applied the fixes, so the closure is evidenced rather than assumed.
Institutional first, private clients by exception
Our institutional practice is the primary focus. We act for security teams inside large organisations, on retainer and on named engagements.
For private individuals we accept a small number of bespoke mandates each year. Those are reserved for technically complex threats, and our most senior principals lead them directly. In short, it is the same standard of attention, opened to a handful of people who genuinely need it.
We do not actively market that side of the practice. Since capacity is the constraint, we also reserve the right to decline work that falls outside our technical rigour.
“We do not publish client names. References come on an NDA call.”
A logo strip proves nothing, because logos can be copied from anywhere. Instead we offer a redacted report, a named practitioner, and a reference call once the NDA is signed.
Every project is a fixed fee, agreed after we understand the threat model. Therefore the invoice never grows because a test took longer than expected.
Proof a certified hacker should be judged on
Anyone can claim competence, so we would rather show a fragment of the work. Below is a redacted finding from an authorised engagement, presented the way it reaches the client.
- Client
- Retail group, North America
- Entry point
- Exposed continuous integration runner token
- Chain
- Runner token to service account to vault path to domain administrator
- Time to impact
- 41 hours from kickoff
- Business impact
- Full control of the production identity plane
- Remediation
- Three configuration changes, zero downtime, verified on retest

A retail group, domain administrator in 41 hours
No scanner would have flagged that path, because each step looked harmless alone. Our principal chained them, proved the impact, and handed over three fixes. The client closed all three without downtime.
Fixed fees, scoped after we talk
Most engagements settle between $35,000 and $120,000, depending on scope.
We quote a fixed fee after a scoping conversation, so there is no hourly billing and no change orders. However, if your budget sits below $15,000 we are probably the wrong firm, and we will say so plainly.
Commitments we put in writing
These are the assurances a buyer of sensitive work needs. Moreover, they belong on the page rather than buried in the terms.
- Authorisation firstWe test only systems you own or are explicitly authorised to test.
- Non-disclosure as standardSigned before any technical discussion, so nothing is shared first.
- No retention of findingsYour data and results are destroyed once the project closes.
- No subcontractingThe named practitioner does the work, because handoffs lose context.
- Insured and clearedErrors and omissions cover, plus background-checked practitioners.
- Encrypted throughoutEvidence and reports move over encrypted channels only.
Questions about hiring a certified hacker
Is hiring a certified hacker legal?
Yes, provided the work is authorised. A certified hacker tests only systems the client owns or has written permission to test. Because authorisation is the dividing line, we require it in writing before any engagement starts.
Which certifications should a certified hacker hold?
Look for practical, examined credentials such as OSCP, OSEP, or CREST. In addition, United Kingdom government work requires the CHECK scheme. Certifications that rely on multiple-choice papers tell you far less about capability.
How do I check a certified hacker's credentials are real?
Ask for the practitioner's name and certification number, then search the issuing body's registry. OffSec and CREST both publish one, so the check takes about a minute. We supply those details on the first call.
Will you work with private individuals?
Our primary practice is institutional. However, we accept a small number of private mandates each year for founders, executives and families with a genuine threat model. A senior principal leads that work directly.
What does an engagement cost?
Engagements start at $25,000, while most settle between $35,000 and $120,000. We quote a fixed fee after a scoping conversation, so there is no hourly billing. If the budget is materially lower, we will tell you honestly.
What do I receive at the end?
You receive a report with reproducible attack chains, business risk context, and prioritised remediation. Moreover, the practitioner who ran the test briefs you directly. A complimentary retest then confirms your fixes.