Find the hole
before they do.
Derivee runs real penetration tests and red team engagements against real infrastructure, then trains the operators who run the next one. No dashboards pretending to be defense — just evidence, exploit chains, and fixes that hold.
Engagements scoped to how attackers actually get in — not a checkbox scan.
Every engagement ends with a live debrief with the engineers who hold the fix, not just the ones who hold the budget.
Network Penetration Testing
External and internal network testing mapped to a real adversary's initial-access options — not a checkbox vulnerability scan.
02Web & API Security Testing
Manual assessment of authentication, authorization, and business-logic flaws that automated scanners consistently miss.
03Red Team Simulation
Objective-based engagements that test detection and response, not just perimeter defenses — with your SOC in the loop or blind.
04Cloud & Identity Assessment
Misconfiguration and privilege-escalation review across AWS, Azure, and GCP, including the IAM trust paths attackers actually pivot through.
05Social Engineering Assessment
Phishing, vishing, and physical access testing to measure the human layer — reported without naming or shaming individuals.
06Secure Code Review
Source-assisted review of the components that matter most, paired with live testing to confirm which flaws are actually exploitable.
Same phases an attacker uses. We just tell you when it works.
Fixed order because each phase depends on evidence from the last — this is the actual sequence, not a stylistic list.
Scope
Define targets, rules of engagement, and what "success" means for your business, in writing.
Recon
Map the real attack surface: assets, exposed services, identities, and third-party trust.
Exploit
Chain weaknesses into proven impact — data access, lateral movement, privilege escalation.
Report
Evidence-backed findings, severity, and reproduction steps — built for engineers, not slideware.
Remediate
Retest each fix until the finding is closed, not just marked "in progress."
Transparent starting points. Every quote is scoped on the call, not guessed from a form.
Custom scopes, multi-year programs, and Academy team bundles are quoted separately.
Essential Scan
- External or internal network test, or one web app
- Manual testing, not just automated scanning
- Written report with reproduction steps
- One 30-minute debrief call
Full Engagement
- Combined network + web/API testing
- Compliance-ready reporting (SOC 2, ISO 27001, PCI DSS)
- One full round of retesting included
- Live debrief with your engineering team
- 30 days of post-engagement email support
Enterprise Program
- Quarterly or continuous testing cadence
- Red team simulation with purple-team option
- Dedicated engagement lead
- Academy training bundled for your team
Training built by people who still do the work on Monday morning.
Cohort-based, hands-on, graded against live vulnerable infrastructure — not multiple choice.
Ethical Hacking Fundamentals
Networking, Linux, and the legal & reporting foundation every tester needs before touching a target — for career-changers and junior analysts.
Web Application Exploitation
Manual testing against deliberately vulnerable apps: auth bypass, injection, IDOR, and logic flaws — building toward OSWE-style rigor.
Red Team Operations
C2 tradecraft, evasion, and adversary emulation against a monitored range with a live blue team on the other side.
Certified, hands-on testers — the people named in your report signed it themselves.
Upload real photos any time from Appearance → Customize → Derivee — Photos.
OSCE3, 9 years offensive security across fintech and critical infrastructure.
OSWE, built the exploitation curriculum used in the Academy cohorts.
CREST CCSAM, specializes in IAM trust-path and misconfiguration reviews.
What we found on real engagements — and what changed after.
What clients say once the report actually lands.
"Most pentest reports are 40 pages of restated CVSS scores. Derivee's had eleven findings we could actually reproduce and fix the same sprint."
"The red team exercise found a trust relationship between two acquisitions that nobody on either security team knew existed."
"Sent two analysts through the Web Exploitation cohort. Both were shipping real findings in our bug bounty program within a month."
Frequently asked questions
Most engagements run 1–3 weeks depending on scope, followed by a written report and a live debrief. Red team simulations typically run 3–6 weeks.
Yes. Every engagement includes one round of retesting so findings are confirmed closed, not just marked resolved.
Rules of engagement are agreed in writing before testing starts, including which techniques are in or out of scope for production environments, to avoid unnecessary risk of downtime.
A penetration test looks for as many exploitable vulnerabilities as possible in a defined scope. A red team engagement is objective-based and tests detection and response, often without your defenders knowing in advance.
Yes — reports are formatted to satisfy auditor requirements for SOC 2, ISO 27001, and PCI DSS penetration testing evidence requests.
Ethical Hacking Fundamentals assumes no prior security experience, just basic comfort with computers. The two advanced courses do expect that foundation first.
Free: the Attack Surface Checklist
The 20-point checklist our testers run through before scoping any engagement — find your obvious exposure before you pay anyone to find it for you.
Notes from the field, written by the people doing the testing.
No syndicated news, no AI-written listicles — findings, retrospectives, and methodology.
Tell us what you're protecting. We'll scope the rest.
A scope call is 30 minutes with a senior tester, not a salesperson. You'll leave with a rough estimate of timeline and cost.