Process
How a Provecore engagement works
Every engagement follows a structured process from scope request to confirmed fix. The goal is exploitation-backed findings delivered fast enough to be actionable before your next release.
Scope request
Day 0You submit your stack, target surfaces, and goals through our contact form or email. We review and respond within one business day with questions or a proposed approach. No automated quoting — every scope is reviewed by a person.
Outputs
- Scope confirmation
- Engagement type recommendation
- Initial timeline estimate
Scoping call + proposal
Day 1–2A 30-minute call to align on scope, access requirements, authorization boundaries, and timeline. We discuss your tech stack, auth model, and what specific surfaces matter most. You receive a written proposal and SoW within 48 hours.
Outputs
- Proposal document
- Statement of Work
- Rules of Engagement draft
Authorization + kickoff
Day 3You sign the Rules of Engagement authorizing the test. We receive credentials, API documentation (if available), and any relevant context. Kickoff call confirms the test window, communication channel for critical findings, and reporting format.
Outputs
- Signed Rules of Engagement
- Test credentials and access
- Communication protocol confirmed
Testing
Days 4–12 (scope-dependent)Exploitation-led testing across the agreed surfaces. We follow a structured methodology covering authentication, authorization, business logic, input handling, API security, and session management. Critical findings are reported verbally same-day. No scanner-only passes — every finding is manually validated.
Outputs
- Same-day verbal notice for critical findings
- Live notes for your team if requested
- Testing log
Report delivery
2 business days after testingYou receive two documents: an Executive Summary for leadership and procurement reviewers, and a Technical Findings Report for your engineering team. Every finding includes: severity, root cause, proof of exploitation, affected endpoint or code path, and step-by-step remediation guidance.
Outputs
- Executive Summary
- Technical Findings Report
- Remediation guidance per finding
Findings walkthrough
Optional, same weekA 45–60 minute call to walk your engineering team through the findings, answer questions, clarify reproduction steps, and prioritize remediation order. This is optional but reduces ambiguity significantly.
Outputs
- Engineering Q&A session
- Prioritized remediation roadmap
Retest + confirmation
Within 30 days of deliveryAfter your team applies fixes, we retest each finding, verify remediation, and issue a written Retest Confirmation Letter. This letter confirms the specific issues tested and their status — suitable for inclusion in SOC 2 packages, vendor security questionnaires, or customer requests.
Outputs
- Retest Confirmation Letter
- Updated findings status
- Remediation evidence package
Authorization is mandatory
We do not begin any testing without a signed Rules of Engagement document from an authorized representative of the target organization. This is not a formality — it is a non-negotiable requirement for every engagement.
Authorized testing policy · Read our full legal notice