Skip to main content
SurfaceShield Logo
SurfaceShield

How it works

From the initial scoping conversation to the post-remediation re-test, every phase of a SurfaceShield assessment is predictable, transparent, and non-destructive.

Core Differentiator

Written authorization precedes every packet

We never probe arbitrary targets or launch unannounced tests. Mutual authorization ensures legal compliance, protects third-party hosting terms, and prevents accidental interference with production services.

STANDARD: RFC 9116 / BILATERAL RULES OF ENGAGEMENT
Methodology Sequence6-STAGE LIFECYCLE
01

Understand

TIMELINE: Day 1
Footprint Exploration & Context

We begin with a brief exploratory review of your business operations. What web properties do you own? Do you operate an online store, customer portal, or public APIs? Where are your primary DNS records hosted?

Deliverable
Initial Discovery Manifest
Client Action
Provide high-level domain names and any external vendor relationships.
02

Scope

TIMELINE: Days 1–2
Precision Target Schedule Definition

Every assessment requires an explicit, bounded target schedule. We catalog all relevant subdomains, IP ranges, and services. We explicitly separate customer-owned assets from shared multi-tenant SaaS providers.

Deliverable
Authorized Target Schedule
Client Action
Review and approve the target schedule document.
03

Authorize

TIMELINE: Day 2
Bilateral Written Rules of Engagement

Both parties sign a formal Authorization to Test agreement. This legal document establishes testing windows, emergency contact protocols, authorized source IP addresses, and explicit boundaries.

Deliverable
Signed Legal RoE & Scope Charter
Client Action
Execute the bilateral Authorization to Test agreement.
04

Assess

TIMELINE: Days 3–5
Non-Destructive External Probing

We execute polite, observational scans and manual evaluations across the approved perimeter. We test DNS integrity, mail protocols, TLS suites, open ports, application security headers, and information leakage.

Deliverable
Raw Evidence & Response Logs
Client Action
None required. Business operations continue with zero interruption.
05

Report

TIMELINE: Day 6
Executive Presentation & Technical Evidence

You receive the finished assessment report. We hold a 1:1 video consultation with your leadership and technical staff to explain findings, business impact, and answer questions directly.

Deliverable
Executive Summary & Technical Evidence PDF
Client Action
Attend the 45-minute findings debrief consultation.
06

Verify

TIMELINE: Days 14–30 (Post-Fix)
Remediation Confirmation Re-Test

After your developers implement the recommended patches or firewall rules, we conduct a targeted verification re-scan to confirm the exposure has been successfully resolved.

Deliverable
Verification Letter of Closure
Client Action
Notify SurfaceShield once fixes are deployed.

Initiate your assessment lifecycle

We will review your public digital footprint and draft an authorized target schedule for your review.