About · Kassandra Security · San Diego, CA
A small practice that tests by hand and reports in plain findings.
Kassandra Security is a two-reviewer shop in Mira Mesa. We keep the roster deliberately small so the tester who scoped your engagement is the one who exploits it, writes it up, and re-tests the fix.
01 — Why we started
Built on the reports we wished vendors had sent
Before Kassandra, our founder spent six years on the buying side — engineering lead at a San Diego SaaS company that paid five figures for a “penetration test” and received a re-badged vulnerability scan: 200 pages of severity ratings, no proof of exploit, and nothing an engineer could reproduce on a Tuesday afternoon.
Kassandra Security exists to send the opposite document. Every finding we report has a request you can replay, a screenshot of the outcome, and a remediation step scoped to your stack. If we can’t prove impact, it doesn’t go in the findings table — it goes in the notes.
We stayed small on purpose. A larger bench means work gets handed to whoever is free; we’d rather cap the calendar and keep the same two reviewers on your systems from kickoff to sign-off.
No finding ships without a reproducible request and a remediation step written for your stack.
02 — What we hold to
Four rules the practice runs on
These aren’t posters on a wall. Each one shows up in how a Kassandra engagement is scoped, tested, and closed out.
Prove it, don’t rate it
A scanner tells you a port is “potentially vulnerable.” We chain the misconfiguration, capture the session, and hand you the exact request. Confirmed exploitability over theoretical severity — every time.
Write for the reader who has to fix it
Two audiences read every report: a board that needs the executive summary and an engineer who needs reproduction steps. We write both, in the same document, without padding the CVE count to inflate a page number.
Bound the scope before touching a system
Hosts, applications, testing windows, and rate limits are signed off in the scoping document. Destructive checks stay out unless you authorize them in staging. Your production stays up; your invoice doesn’t drift.
Close the loop with a real retest
An engagement isn’t done when the PDF lands. Once you remediate, we re-test each finding and mark it resolved with evidence — one verification pass built into the fee, never an upsell.
03 — Who you’ll actually work with
The people on your engagement
No account manager relay, no offshore hand-off. You talk to the testers doing the work and the lead coordinating it — the same three from the scoping call to the retest sign-off.
Offensive security
Runs external, web-app, and cloud-configuration engagements end to end — recon through manual exploitation. Twelve years across SaaS and fintech environments, OSCP and OSWE held current. Scopes what they test; tests what they scope.
Second set of eyes
Handles internal network testing and phishing programs, and reviews every report before it ships — validating each finding’s reproduction steps against the raw evidence. Nothing reaches your inbox unread twice.
Scope & compliance
Owns the scoping document, rules of engagement, and SOC 2 mapping. Keeps testing windows honest and translates findings into a gap register your auditor will accept as evidence for CC4.1 and CC7.1.
Small on purpose
We cap the number of concurrent engagements so no one is stretched across five clients at once. If our calendar is full, we’ll tell you the next open window rather than hand your systems to a subcontractor.
04 — Start a conversation
Tell us what you run — we’ll scope it
Whether you already know you need a pentest or you’re just staring down a first SOC 2 audit, send a few details. We reply within one business day with a fixed-fee scoping proposal — no discovery funnel, no sales sequence.
- Weekday replies within one business day
- NDA signed before any technical detail
- San Diego on-site · remote across the U.S.
