How it works
Six steps. The same discipline, every incident, every time zone.
This is the exact process a senior engineer runs on your site. No improvisation, no mystery — and every step lands on your private incident page as it happens.
Triage
You tell us what you are seeing. Automated first checks run while you type, a senior engineer is paged, and the incident clock starts.
Contain
A forensic copy of the site and logs is taken before anything is changed. Active damage is stopped and customer data protected.
Find the way in
We identify the root cause — the vulnerable component, stolen credential or misconfiguration — because a cleanup without root cause is a countdown to reinfection.
Clean and harden
Every injected file, backdoor, rogue account and malicious job is removed, and the restored site ships harder than the one that was hacked.
Verify
Independent re-scans from outside our own tooling prove the site is clean, with before-and-after results you keep.
Hand over
You receive the proof pack: what happened, how they got in, everything we changed, and what to do next — readable by a board and a developer.
A real rescue's shape (details anonymised). Opened to verified-clean in under 10 hours.
The deliverable
The proof pack is the product.
Anyone can say "it's fixed." We hand you the evidence: the incident narrative in plain English, every infected file listed, the entry point named and closed, every change logged, and independent re-scan results. It's what you show your board, your insurer, and anyone who asks "are we sure?"
Inside every proof pack
- — Executive summary (one page, plain English)
- — Timeline of the attack and the response
- — Infected files & what they did
- — Root cause & how it was closed
- — Hardening applied & recommendations
- — Independent verification results