How we work with you

Six ways to work with us, scoped to what you need

Built for companies that ship software but don't have a full security team. Every engagement runs on products we build and operate ourselves, and is scoped with you on a call.

A typical path

  1. 01

    Test

    A pentest or assessment shows where you actually stand.

  2. 02

    Keep testing

    Recurring or continuous testing and managed AppSec catch what each release changes.

  3. 03

    Engineer

    We build the missing controls with your team.

  4. 04

    Lead

    A fractional CISO owns the programme and the audits.

Start wherever you are. Each engagement also stands on its own.

01 · Solution

Compliance Pentest

A scoped penetration test of your web apps, APIs, cloud or network, with a report written for auditors and enterprise buyers. AI agents cover the breadth; our engineers exploit and chain the findings that matter. Our team holds OSCP and CISSP certifications.

For: Teams that need a pentest for SOC 2, ISO 27001, PCI DSS or an enterprise customer.

Runs on DSO

Not ready for a call? Run a free scan with DSO ↗ Free plan, no card: SAST, SCA with reachability, IaC and secret scanning, unlimited seats and repositories.

What's included

  • Scoping call and rules of engagement
  • Agentic recon and testing, then manual exploitation by our engineers
  • Proof of concept and fix guidance for every finding
  • Technical report and executive summary
  • Retest of the findings you fix

02 · Solution

Recurring & Continuous Pentest

Pentesting on the cadence you ship at: recurring engagements, such as quarterly, or continuous testing on a schedule you set. Scheduled scans and agentic pentests run between engagements, and our engineers review what they find and test major releases by hand.

For: Product teams that ship often and are asked for security evidence all year.

Runs on DSO

What's included

  • Recurring manual pentests on a cadence you choose, such as quarterly
  • Continuous scheduled scanning of code, dependencies, secrets and IaC
  • Agentic pentests of the hosts you verify, on your schedule
  • Engineer review of every finding, and manual testing of major releases
  • Fixes proposed as pull requests, retested when merged

03 · Solution

Managed AppSec & Detection

We run application security for you: detection across code, dependencies, packages and APIs, triaged by our engineers, with fixes your team approves.

For: Engineering teams without a dedicated AppSec engineer.

Scope: This covers what your engineers build and ship. It is not an IT SOC, endpoint MDR or 24/7 monitoring of your network and devices.

Not ready for a call? Run a free scan with DSO ↗ Free plan, no card: SAST, SCA with reachability, IaC and secret scanning, unlimited seats and repositories.

What's included

  • Continuous detection across repositories, dependencies and pipelines
  • Malicious and typosquatted packages blocked at install time
  • API security policy kept in step with your OpenAPI spec
  • Triage by our engineers, with fixes as pull requests
  • Monthly report and audit evidence for SOC 2, ISO 27001, PCI DSS and DORA

04 · Solution

Agentic AI Security

Assess, test and engineer controls for the AI agents, MCP servers and LLM features you run: what they can reach, under whose authority, what needs approval, and how every action is logged.

For: Companies giving AI agents access to code, data, infrastructure or customers.

What's included

  • Inventory and threat model of your agents, models and MCP tools
  • Agent and MCP security assessment
  • AI red teaming, including prompt injection and excessive agency
  • Least-privilege tool access, approval gates and audit trails
  • Prompt-injection guards at your API gateway

Related services

05 · Solution

Security Engineering Projects

Fixed-scope projects where we build the controls with your team and hand them over: pipelines, access, supply chain and cloud. You end up with controls your engineers can run.

For: Teams that know what is missing and need senior engineers to implement it.

What's included

  • DevSecOps: security checks in pull requests, pipelines and deployments
  • Zero Trust access to replace your VPN
  • Supply-chain controls, SBOMs and package policy
  • Cloud configuration and IAM hardening
  • Documentation and handover to your engineers

06 · Solution

Fractional CISO

Security leadership without a full-time hire. Our CEO, Zeeshan Sultan, leads your security programme, backed by an advisory board of practitioners from banking, healthcare and govtech. Our team holds CISSP, CISM and CCSP certifications.

For: Companies facing audits, regulators or enterprise buyers without a security leader.

Scope: Incident response here means planning and rehearsal. We don't offer an incident response retainer.

What's included

  • Security strategy, roadmap and risk register
  • Policies, controls and audit coordination
  • Answers to customer security questionnaires
  • Incident response planning and tabletop exercises
  • Executive and board reporting

Pricing

How engagements are priced

We don't publish a rate card, because no two estates are the same. Every engagement is quoted after a scoping call, based on what we would actually test.

You receive a written proposal with a firm quote before any work starts. Any change in scope is agreed with you in writing first.

What the quote is based on

  • The applications, APIs and environments in scope
  • The depth of testing
  • Whether it runs once, on a recurring cadence or continuously

What happens after the call

  1. 01

    Scoping call

    You talk it through with the engineers who would do the work.

  2. 02

    Written proposal

    Scope, approach, deliverables and a firm quote, in writing.

  3. 03

    Kickoff

    Once the proposal is signed, we agree the rules of engagement in writing and start.

How we test, handle your data and use AI is set out on our Trust page.

Looking for something specific?

All 26 services

Red teaming, smart-contract audits, IT/OT testing, training and more are available as standalone engagements.

Browse all services →

Book a call

Book a 30-minute call

Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.

Logo

Cyphlon

1:1 Consultation Call

30 min Google Meet

An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.

Logo Cyphlon

Research and tool releases by email

Unsubscribe any time. Privacy Policy

About Us

Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.

[email protected]

© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016

Privacy Policy Terms of Use