No. Before any test we define the rules of the work with you: what will be assessed, when and how. Every action is controlled and non destructive. Our role is to identify and confirm the findings, not to cause the damage a criminal would cause. Nothing is deleted, altered or taken offline. If you prefer, the tests can run in a staging environment, without touching the system that serves your customers.
It does, and that is why the reports speak two languages. You get a summary in business language, with the risks found and what should be resolved first. Whoever looks after your systems, whether a vendor, a software house or an internal professional, gets the technical step by step for each fix. And if no one is looking after this today, Safe Jornada, our continuous engagement, works as your outsourced security department.
An executive report in business language, a risk matrix with every finding classified by severity, a prioritized remediation plan, a technical report with the evidence and reproduction steps for each vulnerability, and the Test Certificate. It is the document banks, large clients and auditors ask for when they want evidence rather than promises, and it is the kind of testing evidence that ISO 27001 and PCI DSS processes usually require. If your operation uses AI, the package also includes the AI layer report, with the prompt already hardened.
It depends on the size of what will be assessed. One time packages are sized between 40 and 160 hours of technical work, which in practice means a few weeks between the start of testing and the delivery of the reports. It all starts with a scoping conversation, and the proposal comes out with the schedule and the delivery date already set.
All work is covered by a non disclosure agreement and by scope rules defined in the contract. We access only what is needed to confirm the findings, in a controlled way, and report distribution is restricted to the people you authorize. We operate in line with applicable data protection law, and the test itself helps your company demonstrate the diligence the law requires.
They are different things, and both remain necessary. A firewall and antivirus are automated defenses. The Safe test does the opposite: it simulates a human attacker trying to get in, to find out what gets past those defenses. Most successful attacks exploit exactly what those tools cannot see, such as configuration errors, gaps in login screens and systems exposed to the internet for no reason.
Yes, and this is where we stand apart. AI assistants and agents can be manipulated into leaking information, bypassing business rules or answering on behalf of your brand in ways you never approved. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider's last update. You receive the prompt already hardened. Traditional security firms do not test this, because they do not build AI. GenIA does.
Safe Pontual is the snapshot: a package of hours with a full assessment, risk matrix, remediation plan and certificate. It fits audits, go lives, compliance requirements, due diligence or periodic reassessment. Safe Jornada is the operation: a monthly subscription in which we act as your security team, with a live risk backlog, test and retest sprints, an executive committee and continuous maturity growth. If you need to prove something now, start with Pontual. If you need to keep it that way, start with Jornada.
It depends on the scope: how many systems will be assessed, in which environments, at what depth, and whether retesting is needed. We define that with you in the first conversation, and the proposal comes out with the price and the timeline already set, with no surprises later. One time packages are sized in hours, from 40 to 160, and continuous engagement is monthly.