Process

How a Provecore engagement works

Every engagement follows a structured process from scope request to confirmed fix. The goal is exploitation-backed findings delivered fast enough to be actionable before your next release.

01

Scope request

Day 0

You submit your stack, target surfaces, and goals through our contact form or email. We review and respond within one business day with questions or a proposed approach. No automated quoting — every scope is reviewed by a person.

Outputs

  • Scope confirmation
  • Engagement type recommendation
  • Initial timeline estimate
02

Scoping call + proposal

Day 1–2

A 30-minute call to align on scope, access requirements, authorization boundaries, and timeline. We discuss your tech stack, auth model, and what specific surfaces matter most. You receive a written proposal and SoW within 48 hours.

Outputs

  • Proposal document
  • Statement of Work
  • Rules of Engagement draft
03

Authorization + kickoff

Day 3

You sign the Rules of Engagement authorizing the test. We receive credentials, API documentation (if available), and any relevant context. Kickoff call confirms the test window, communication channel for critical findings, and reporting format.

Outputs

  • Signed Rules of Engagement
  • Test credentials and access
  • Communication protocol confirmed
04

Testing

Days 4–12 (scope-dependent)

Exploitation-led testing across the agreed surfaces. We follow a structured methodology covering authentication, authorization, business logic, input handling, API security, and session management. Critical findings are reported verbally same-day. No scanner-only passes — every finding is manually validated.

Outputs

  • Same-day verbal notice for critical findings
  • Live notes for your team if requested
  • Testing log
05

Report delivery

2 business days after testing

You receive two documents: an Executive Summary for leadership and procurement reviewers, and a Technical Findings Report for your engineering team. Every finding includes: severity, root cause, proof of exploitation, affected endpoint or code path, and step-by-step remediation guidance.

Outputs

  • Executive Summary
  • Technical Findings Report
  • Remediation guidance per finding
06

Findings walkthrough

Optional, same week

A 45–60 minute call to walk your engineering team through the findings, answer questions, clarify reproduction steps, and prioritize remediation order. This is optional but reduces ambiguity significantly.

Outputs

  • Engineering Q&A session
  • Prioritized remediation roadmap
07

Retest + confirmation

Within 30 days of delivery

After your team applies fixes, we retest each finding, verify remediation, and issue a written Retest Confirmation Letter. This letter confirms the specific issues tested and their status — suitable for inclusion in SOC 2 packages, vendor security questionnaires, or customer requests.

Outputs

  • Retest Confirmation Letter
  • Updated findings status
  • Remediation evidence package

Authorization is mandatory

We do not begin any testing without a signed Rules of Engagement document from an authorized representative of the target organization. This is not a formality — it is a non-negotiable requirement for every engagement.

Authorized testing policy · Read our full legal notice