Skip to content

Services

Three tracks, ten engagements, one tester.

Every engagement is fixed fee with a written scope and rules of engagement agreed before testing begins, one round of retesting included, and a report with a signed attestation letter naming the practitioner who did the work.

Track A

Compliance-driven testing

Testing scoped to produce the evidence an assessor, auditor or examiner will actually accept — and an attestation letter with a named practitioner behind it.

CMMC readiness pentest

from $18,000

Scoped to Level 2 and Level 3 evidence, mapped to the practices your assessor will test, with an attestation letter for the package.

  • Scope and boundary review
  • CUI enclave testing
  • Practice-to-evidence mapping
  • Attestation letter

Typical duration · 7–8 days

SOC 2 evidence pentest

from $14,000

A manual, human-led test producing evidence against CC4.1 — and the artifact your enterprise customers ask for by name once they have read your SOC 2 report.

  • External and application scope
  • Manual exploitation
  • TSC-mapped findings
  • One retest

Typical duration · 6 days

PCI DSS v4.0 segmentation and pentest

from $16,500

Cardholder data environment scoping, segmentation validation, and Requirement 11.4 testing.

  • CDE scope validation
  • Segmentation testing
  • Internal and external
  • Remediation retest

Typical duration · 7 days

Track B

Offensive testing

The core work. Automated tooling runs the breadth; the hours you pay for go into exploitation, chaining, business-logic abuse, and the write-up.

External network and perimeter

from $9,500

Everything reachable from the internet: attack surface discovery, exposure analysis, exploitation, and a prioritised remediation plan.

  • Up to 25 hosts
  • OSINT and attack surface mapping
  • Exploitation
  • One retest

Typical duration · 4 days

Web application

from $14,000

Authenticated testing across roles. OWASP coverage is the floor — the value is in access-control and business-logic flaws a scanner cannot model.

  • One application, all roles
  • Authorisation and IDOR
  • Business logic
  • One retest

Typical duration · 6 days

Cloud configuration and pentest

from $14,500

AWS or Azure. Identity, network, and data-layer review, then exploitation of what the configuration actually permits.

  • One account or subscription
  • IAM and privilege paths
  • Network and data exposure
  • One retest

Typical duration · 6 days

Internal network and assumed breach

from $16,500

Starts from a foothold rather than arguing about whether one is possible. Lateral movement, privilege escalation, and Active Directory.

  • On-site or shipped implant
  • Lateral movement
  • Active Directory
  • Domain privilege paths

Typical duration · 7 days

Track C

AI and ML systems

The practice this firm is committing to. Not only the model — the infrastructure it trains on, the pipeline that feeds it, the agents that act on its output, and the architecture that is supposed to contain all three. Rarely available from a firm this size, because it needs someone who has done offensive work against shipping systems rather than someone who read the guidance last quarter.

AI and LLM red team

from $16,000

Prompt injection, jailbreaks, tool and agent abuse, training and retrieval data leakage. Mapped to the OWASP Top 10 for LLM Applications and the NIST AI RMF Generative AI Profile.

  • Model and application layer
  • Agentic tool abuse
  • Data leakage
  • OWASP LLM / NIST AI RMF mapping

Typical duration · 5 days

AI red team evidence package

from $21,000

The red team engagement plus the documented evidence trail an ISO 42001 audit, a NIST AI RMF MEASURE/MANAGE mapping or an enterprise AI security review asks for.

  • Full red team engagement
  • Run, failure and mitigation log
  • Framework control mapping
  • Attestation letter

Typical duration · 7 days

ML pipeline and training infrastructure test

from $18,000

The path from data to deployed model, tested as an attack surface: ingestion and labelling, feature stores, experiment tracking, artefact registries, and the CI that promotes a model into production. Where a poisoned input or a writable artefact store turns into inference-time control.

  • Data ingestion and labelling path
  • Feature store and artefact registry access
  • Training and orchestration plane
  • Model promotion and CI/CD boundary

Typical duration · 6 days

AI infrastructure penetration test

from $18,000

The estate the models actually run on. Identity and role assumption across training and inference accounts, GPU and notebook environments, vector store exposure, model and inference endpoint authorisation, and the tenancy boundaries between them.

  • Cloud identity and role chains
  • Notebook and training environment escape
  • Vector store and retrieval exposure
  • Inference endpoint authorisation

Typical duration · 6 days

AI security architecture review

from $12,000

A design-stage review rather than a test: trust boundaries, tool and agent permissions, data flow and retention, tenant isolation, and the failure modes that a penetration test will find later and more expensively. Delivered as a findings register with a prioritised remediation sequence.

  • Trust boundary and data flow review
  • Agent and tool permission model
  • Tenant isolation design
  • Prioritised remediation register

Typical duration · 4 days

Incident response tabletop

from $4,500

A facilitated exercise built on a scenario specific to your business, with a written after-action report.

  • Custom scenario build
  • Facilitated session
  • After-action report
  • Gap register

Typical duration · 2 days

Deliverable

What arrives at the end.

A report that has to survive being read by someone who was not in the room — an assessor, an auditor, or your customer's security team.

  1. 01

    Executive summary

    One page, written for a reader who will not read the rest. What was tested, what was found, what it means for the business, and what to do first.

  2. 02

    Findings

    Each with severity, the evidence, reproduction steps that actually reproduce, business impact in your context rather than a generic description, and specific remediation.

  3. 03

    Remediation plan

    Ordered by risk against effort, so the list is workable rather than merely complete.

  4. 04

    Attestation letter

    Named practitioner, credentials, scope, dates and methodology. Signed. This is the page your assessor or customer asks for.

  5. 05

    Retest report

    After you fix, Zero Harbor Security verifies, and the report is reissued showing what closed.

Rates

Work that is not a package.

Retesting beyond the one included round, advisory time, expert witness support and anything scoped by the hour.

Assessment and testing
$275 / hour
AI red team, device testing
$325 / hour
Day rate, on-site
$2,200 / day
Advisory retainer
$2,500 / month

Scope

What moves the number.

So the fixed fee stays fixed. If any of these apply, say so up front and the quote accounts for it.

  • Size of the estate

    Host counts, application count, number of user roles, and how many cloud accounts are in scope.

  • Testing window

    Out-of-hours or weekend testing, or a change freeze that compresses the window.

  • Travel

    On-site internal or physical testing outside the Atlanta metro is billed at the day rate plus travel.

  • Evidence depth

    Compliance engagements that need practice-by-practice mapping take longer than a findings report.

  • Retests

    One round is included. Further rounds are hourly.

  • Rush

    A date inside three weeks, where it can be taken at all, carries a premium. Often it simply cannot.

Comparison

Why this and not a platform.

A continuous testing platform will sell you a year of automated external testing with unlimited retests for roughly the price of one thorough manual engagement. That is a real offer and for some organisations it is the right one.

Buy the platform if what you need is coverage — knowing quickly when something new is exposed, across a large and changing estate.

Buy an engagement if what you need is an artifact: a report an assessor, an auditor, an examiner or an enterprise customer's security review will accept, with a named practitioner attesting to it. A platform cannot sign anything, and the document has to survive being forwarded to somebody who was not in the room.

Most organisations past a certain size eventually need both.

Scope a test