A defined boundary
Proposed scope: the assets, questions, exclusions, permissions and conditions that govern the work.
Security audits, penetration testing and security assessment. Start with the system, the concern and the decision you need to make.
A security concern is difficult to act on when the boundaries are unclear. The first task is to distinguish what is known, what needs checking and what testing is actually authorized.
| Method | Question and scope |
|---|---|
| Security audit | Do the agreed requirements or controls hold up? A review against agreed requirements or controls. Useful when you need to understand the evidence behind an existing security position. |
| Penetration testing | Where might an authorized system be exploitable? An agreed attempt to identify exploitable weaknesses in specifically authorized systems. Scope, access and testing limits must be settled before activity begins. |
| Security assessment | What needs investigating before the next decision? A broader examination of a defined security concern. Useful when you first need to decide what to investigate, change or test in greater depth. |
Proposed scope: the assets, questions, exclusions, permissions and conditions that govern the work.
Proposed output: observed issues, supporting evidence, impact and limitations, with priorities explained rather than presented as a score alone.
Proposed output: remediation options and any agreed follow-up checks. Retesting is a separate scope decision.
These are proposed scoping topics, not a fixed package or a delivery promise. Methods, outputs, responsibilities, timing and fees need to be confirmed before an engagement.
Keep the first message high-level. Do not include passwords, access tokens or confidential records.
It depends on the question. An audit examines agreed requirements or controls; penetration testing investigates exploitable weaknesses within an authorized scope. Describe the decision you need to make before choosing the method.
No. A public address does not establish permission. Asset ownership, written authorization, scope and testing conditions need to be agreed first.
No. An assessment provides evidence within its scope and at a particular time. Its limits, exclusions and remaining uncertainty should be explicit.
Send a high-level description of the system and your concern. Do not send passwords, access tokens, exploit code or confidential technical material through the initial contact form.
Use the Security / Responsible Disclosure page for a concern about NovaGrex itself. This division inquiry is for discussing a potential security engagement.
An outline is enough to begin. Tell us the situation and the decision you need to make.
Discuss a security concern