About · Kassandra Security · San Diego, CA

A small practice that tests by hand and reports in plain findings.

Kassandra Security is a two-reviewer shop in Mira Mesa. We keep the roster deliberately small so the tester who scoped your engagement is the one who exploits it, writes it up, and re-tests the fix.

Founded
Independent since 2019, working out of San Diego
Focus
Manual offensive testing and SOC 2 readiness — not resold scans
Bench size
Two senior testers, one project lead — the same faces every engagement

01 — Why we started

Built on the reports we wished vendors had sent

Before Kassandra, our founder spent six years on the buying side — engineering lead at a San Diego SaaS company that paid five figures for a “penetration test” and received a re-badged vulnerability scan: 200 pages of severity ratings, no proof of exploit, and nothing an engineer could reproduce on a Tuesday afternoon.

Kassandra Security exists to send the opposite document. Every finding we report has a request you can replay, a screenshot of the outcome, and a remediation step scoped to your stack. If we can’t prove impact, it doesn’t go in the findings table — it goes in the notes.

We stayed small on purpose. A larger bench means work gets handed to whoever is free; we’d rather cap the calendar and keep the same two reviewers on your systems from kickoff to sign-off.

A Kassandra Security tester at work in low, warm light
Working principle

No finding ships without a reproducible request and a remediation step written for your stack.

02 — What we hold to

Four rules the practice runs on

These aren’t posters on a wall. Each one shows up in how a Kassandra engagement is scoped, tested, and closed out.

01

Prove it, don’t rate it

A scanner tells you a port is “potentially vulnerable.” We chain the misconfiguration, capture the session, and hand you the exact request. Confirmed exploitability over theoretical severity — every time.

02

Write for the reader who has to fix it

Two audiences read every report: a board that needs the executive summary and an engineer who needs reproduction steps. We write both, in the same document, without padding the CVE count to inflate a page number.

03

Bound the scope before touching a system

Hosts, applications, testing windows, and rate limits are signed off in the scoping document. Destructive checks stay out unless you authorize them in staging. Your production stays up; your invoice doesn’t drift.

04

Close the loop with a real retest

An engagement isn’t done when the PDF lands. Once you remediate, we re-test each finding and mark it resolved with evidence — one verification pass built into the fee, never an upsell.

03 — Who you’ll actually work with

The people on your engagement

No account manager relay, no offshore hand-off. You talk to the testers doing the work and the lead coordinating it — the same three from the scoping call to the retest sign-off.

Founder & lead tester

Offensive security

Runs external, web-app, and cloud-configuration engagements end to end — recon through manual exploitation. Twelve years across SaaS and fintech environments, OSCP and OSWE held current. Scopes what they test; tests what they scope.

Senior tester & review

Second set of eyes

Handles internal network testing and phishing programs, and reviews every report before it ships — validating each finding’s reproduction steps against the raw evidence. Nothing reaches your inbox unread twice.

Project lead

Scope & compliance

Owns the scoping document, rules of engagement, and SOC 2 mapping. Keeps testing windows honest and translates findings into a gap register your auditor will accept as evidence for CC4.1 and CC7.1.

How the work splits

Small on purpose

We cap the number of concurrent engagements so no one is stretched across five clients at once. If our calendar is full, we’ll tell you the next open window rather than hand your systems to a subcontractor.

OSCP OSWE CISSP SOC 2 mapping NDA both directions

04 — Start a conversation

Tell us what you run — we’ll scope it

Whether you already know you need a pentest or you’re just staring down a first SOC 2 audit, send a few details. We reply within one business day with a fixed-fee scoping proposal — no discovery funnel, no sales sequence.

  • Weekday replies within one business day
  • NDA signed before any technical detail
  • San Diego on-site · remote across the U.S.

Or email hello@kassandrasecurity.com directly.