Most attacks don't require sophistication. They require an unlocked door, an unquestioned face, or a system nobody tested. We start with the highest-probability entry vectors and work outward. If someone can walk in, the rest of your security doesn't matter.
Advanced attackers are a real threat but a low-probability one. The person who actually shows up at your school, your church, or your facility is more likely determined than skilled. They watched a few videos. They tried the door. They followed someone through.
That's the threat we model. We test what a motivated person with basic knowledge would attempt, because that's who most facilities are actually vulnerable to. If you can't stop them, the sophistication of other threats doesn't matter.
We don't test to impress you. We test to show you exactly where you fail against a realistic adversary.
Every test is within your authorized scope. Every finding is documented with time, method, and outcome not just observed and noted.
Every exterior door gets pulled and tested including loading docks, gymnasium entrances, and maintenance access. You'd be surprised how many doors that appear locked aren't. Spring latch bypasses are also tested where applicable.
We time your busy windows during staff arrival, shift changes, and event dismissal, and attempt to enter behind authorized personnel. No challenge, no confrontation. We document whether your staff stops us. Most don't.
You have a system. We test whether your staff actually uses it. We approach the front entrance with a plausible cover story and document exactly how far we get before we're verified, badged, or challenged if at all.
A delivery driver. A contractor. A parent picking up a sick child. We test whether a plausible pretext and confident approach gets us past your entry point. We document what story worked, what stopped us, and what didn't exist.
Spring latch shimming, under-door lever bypass, REX sensor exploitation, and request-to-exit manipulation. These techniques are publicly documented and require minimal skill or equipment. We also test your access card system. Older card technologies can be cloned in seconds with off-the-shelf hardware. We identify whether yours can be.
Can we sit in your parking lot for 20 minutes, map your facility, and photograph access points without anyone approaching? We find out. We also walk your full perimeter for unsecured gates, fence gaps, and access routes that bypass your primary entry controls.
Every engagement starts with a defined scope and a signed authorization. You know what we're testing. Your staff doesn't.
We define exactly what will be tested covering which entry points, which scenarios, and which time windows, and you sign off. A key administrator knows the test is happening. Your staff does not.
We attempt each scenario within the authorized scope. Every attempt is logged with timestamp, method, outcome, and documentation. If a scenario succeeds, we stop and note the finding we do not exploit further than the scope requires.
You receive a written report of every attempt covering what succeeded, what failed, and why. We debrief with your leadership and translate each finding into a specific, prioritized recommendation you can act on.
When a report says "we got in at 10:14 AM and remained in the hallway for 11 minutes before any staff interaction" that conversation is over. There's nothing to argue about and no ambiguity about priority.
That's what our report gives you. Not a checklist of things that should be better. A timestamped record of what we did, how we did it, and what you need to fix ranked by likelihood of exploitation.
Every scenario attempted, timestamped with method, outcome, and any relevant documentation.
Findings plotted on your facility layout: successful entries, vulnerable perimeter points, and access control gaps marked by location.
Every finding tied to a specific fix, ranked by probability of exploitation and cost to remediate.
A direct conversation with your administration or security team. Findings in plain language with clear next steps.
K–12 campuses, administration buildings, and auxiliary facilities.
Congregations of any size with regular weekly attendance.
Any organization with physical facilities, staff, and public-facing operations.
Utilities, energy facilities, and other regulated physical environments.
Find out where you're actually vulnerable before someone else does.
Schedule a ConsultationEngagements include a full scope document and signed authorization before any testing begins.