2026.01.15

A scoped, time-boxed assessment against a defined surface. The most common engagement shape we run.

What’s in scope

We do not test customer-leased on-premises hardware, third-party SaaS we don’t host, or anything you don’t have written authorization to test.

How it runs

Gray-box by default: you give us credentials and a staging environment, and we spend the first day in your repo orienting. Black-box engagements are available on request. They add roughly 30% to the timeline and may not reach the same depth, since we spend time rediscovering what gray-box access would have shown us up front.

Two-week minimum. Four-week typical. We file findings live in your tracker as we discover them, so your team can start fixing on day three instead of waiting for a final PDF.

What you walk away with

// what the report looks like We publish a redacted sample on request. Email hello@yetisecurity.cz and we’ll send a PDF inside an hour.