How RETIS approaches every engagement
Precise language, every time
RETIS distinguishes risk assessment, security gap assessment, vulnerability assessment, penetration testing, compliance readiness advisory, and statutory audit — clearly, on every page where the distinction matters. We do not claim to provide statutory audits, certifications, or guaranteed compliance unless the relevant legal or professional requirements are actually satisfied.
Authorisation before any testing
All technical security testing — vulnerability assessment, penetration testing, or any activity that probes a live system — is conducted only under an explicit, agreed scope and documented rules of engagement. Nothing is tested based on a website form submission alone.
The RETIS methodology
Every engagement follows the same eight-stage process: Discover, Assess, Score, Prioritise, Remediate, Test, Validate, Monitor. This isn't a marketing framework — it's the literal sequence used from the first discovery conversation through to how findings get tracked over time.
Know exactly what your engagement covers
Every proposal states scope explicitly — what's included, what determines the final price, and what isn't covered. We would rather scope a smaller engagement precisely than oversell a larger one vaguely.
Honest reporting, including what we don't know
Where RETIS doesn't yet have verified information — a case study pending client authorisation, a research report still in development — the site says so plainly rather than filling the gap with placeholder content.
