Locks, badges, and people. We test the physical path into your building — tailgating, badge cloning, lock bypass, and on-site social engineering.
Request this engagement ▸Targets, boundaries, and safety rules defined in writing — including a signed authorization letter carried on-site for the duration.
Site layout, badge systems, staff patterns, and the blind spots a real intruder would find first.
Building the cover story and access approach the attempt will run on.
Attempting real entry through the weakest point found — the same way a motivated intruder would.
Once inside, testing how far the access actually reaches — server rooms, restricted areas, cash handling.
How each weakness was first spotted, how it was abused, and what it exposed — narrated with photo and video evidence.
Verifying the fixes actually hold against the same approach.
…or any organization with a physical location worth protecting — cash handling, server rooms, or restricted areas.
Engagements follow PTES physical-testing methodology and are benchmarked against ISO/IEC 27001 Annex A physical security controls.
Yes. Every engagement carries a signed authorization letter naming the testers, scope, and dates, held on-site for the duration.
That risk is part of why the authorization letter exists. Testers carry it at all times, and a point of contact on your side is on standby to de-escalate if anyone is stopped.
Agreed in scope beforehand — always excluding force, damage to property, and anything posing a genuine safety risk.
Yes, by default. On-site social engineering — pretexting, tailgating cooperation — is part of the assessment unless you scope it out.
Tell us about your site and what you're worried about. We'll come back with a scope, a timeline, and a quote.
Request engagement ▸