Authorization first
No engagement starts without written scope and permission from the system owner.
About Fetion Security
Fetion Security (飞讯安全) helps organizations find weaknesses in websites and web applications, then close them. We are built for teams that need a report they can act on — not a pile of unverified scanner noise.
Our work is scoped, authorized, and documented. You get a ranked view of risk, practical remediation guidance, and a retest so “fixed” means verified.
We work in English and Chinese. Engagements start only with written authorization from the system owner. Findings, evidence, and reports stay confidential and are used only to perform the work you asked for.
No engagement starts without written scope and permission from the system owner.
We verify findings and rank them so engineers spend time on what actually matters.
Discovery without remediation leaves you exposed. We stay available through the patch and the retest.
If you are comparing firms, these four questions matter more than a logo wall.
Anyone willing to scan a live site without written permission is not a vendor you want.
A raw scanner export wastes engineering time. Ask who reproduces each issue.
A PDF alone is not remediation. Ask how they support the patch.
“Closed in Jira” is not the same as “closed in production.” Ask for verification.