Lux-Nous Consult
Frequently asked

Answers before the scoping call.

The questions clients ask most often before their first engagement. If yours isn't here, the contact form gets a senior consultant within four business hours.

All Engagement Methodology Pricing Confidentiality
How long does a typical pentest take?
Most web and network engagements run four to six weeks end-to-end: one week to scope, two to three weeks of active testing, one week to report, plus a retest window. Red team operations run longer. We give a firm timeline in the written proposal — not a range.
Will a junior consultant run our engagement?
No. Every Lux-Nous engagement is personally led by a senior consultant. The person who scopes the work is the same person who runs it and writes the report. We don't grow junior staff on client environments.
How do you handle sensitive data we don't want exfiltrated?
Mutual NDA before scoping. Sensitive scopes have clear data-handling rules in the rules of engagement: no exfiltration, evidence captured to a secured artifact (hash + screenshot), encrypted at rest, access-controlled to the assigned team only. We never retain client data beyond the retention window agreed in the SoW.
Do you provide a retest after we fix findings?
Yes — one free retest of every fixed finding is included in every engagement. The retest produces an updated report suitable for auditors and boards.
How do you price an engagement?
Day-rate against a scoped time window. We give a fixed quote in the written proposal so there are no surprise overages. Variable scope (e.g. mid-engagement scope expansion) is handled by a written change order, never by a verbal "just look at this too."
Can we share your report with our auditor or customers?
Yes. The standard deliverable is audit-grade and acceptable to SOC 2, ISO 27001, PCI, and HIPAA assessors. We also produce a customer-shareable executive summary on request.
Will you publish us as a client?
Only with explicit written consent. We never reference a client publicly without it. Our default is silent — we'd rather lose a logo than break a confidence.
What methodologies do you align to?
PTES, OWASP WSTG (web), NIST SP 800-115 (network), and MITRE ATT&CK (red team). Applied with judgment, not as a checklist — and we tell you what we skipped and why.
Do you offer continuous testing or just point-in-time?
Both. Point-in-time engagements for compliance and major release milestones; quarterly continuous programs for SaaS clients shipping fast. Continuous engagements come with a dedicated consultant assignment so context isn't rebuilt every quarter.

Ready to see what an adversary would actually find?

Book a scoping call →