After the assessment

Security reviews between full pentests.

Book a review when a sensitive feature changes, a finding needs a decision or a fix needs to be tested.

Best fit
After an assessment
A known product, team and risk profile.
Timing
Booked when needed
Around releases, sensitive features and remediation.
Boundary
Defined work
Not an open-ended retainer or staff augmentation.

When to use it

The product changed. The last report did not.

A full pentest is not always the right answer to one new permission model, integration or critical fix.

Smaller reviews can be agreed around that change. You know what will be examined, what evidence will be returned and when another full assessment is warranted.

Before implementation

Review a sensitive flow, its trust boundaries and likely abuse cases.

During remediation

Resolve uncertainty in a finding and work through the proposed fix with its owner.

Before release

Test the changed path and record what was verified.

Boundary

What this service does not cover.

Perspican does not take ownership of your security programme, act as a fractional CISO or provide unlimited on-call support. Each piece of work has an agreed scope and date.

Other services

Where the work usually starts.

When a verified fix requires production code, remediation engineering is available as a scoped add-on.

What changed since the last test?

Send the change, release date and relevant finding or previous assessment.