Fetion SecurityFetion SecurityFind it. Fix it. Verify it.

Methodology

A controlled process, not a noisy scan dump.

Reports are useful only if findings are real, ranked, and fixable. We combine tooling with review, then stay through remediation and retest.

  1. 01

    Authorization and scope

    Written permission, in-scope hosts and apps, out-of-scope systems, and a testing window. Production vs staging is agreed up front.

  2. 02

    Discovery

    Map the attack surface: technologies, entry points, APIs, and accounts you provide for authenticated work.

  3. 03

    Testing

    Automated scanning plus manual verification to cut false positives and catch issues scanners miss — especially in business logic.

  4. 04

    Reporting

    Severity using industry-standard ratings, impact in plain language, evidence, and a recommended fix path. Reports stay confidential.

  5. 05

    Remediation

    We walk through the report with your team and, when requested, help implement the change.

  6. 06

    Retest

    Closed findings are verified. Remaining items stay open with a clear status — not silently dropped.

How we talk about severity

Ratings combine technical ease with business impact. A flaw that exposes one public blog comment is not the same as one that exposes every customer’s orders.

Critical

Straightforward path to wide data exposure, account takeover, or system control. Fix immediately.

High

Serious impact with a realistic exploit path — for example cross-user data access. Schedule promptly.

Medium

Real weakness with a narrower blast radius or extra conditions. Do not ignore; plan the fix.

Low

Hardening, defense-in-depth, or limited impact. Useful, but not the first ticket.

False positives

Scanners over-report. We reproduce what we can and keep unverified scanner noise out of the main list. If something cannot be confirmed in the timebox, we say so instead of padding the report.

Rules on production

  • No denial-of-service or traffic floods.
  • No destructive payloads against live data unless you authorize a specific, contained check.
  • High-impact tests are discussed before they run.
  • Credentials you provide are used only for the engagement and handled as confidential.