Enterprise
Working with enterprise
The questions a procurement team, a vendor risk assessor and a security panel owner ask before a boutique practice gets on the panel. Answered here so you do not have to raise a ticket for them.
Engagement
How engagements are scoped and contracted.
01
Scoping call
Thirty minutes to establish what exists, what it reaches, and whether we are the right practice for it. If we are not, we say so and point you elsewhere.
02
Fixed-fee statement of work
Issued within two business days. Scope, method, deliverables, dates, fee and assumptions in writing. No time-and-materials creep.
03
Authorisation and rules of engagement
For any testing engagement, a separate signed authorisation letter setting targets, methods, time windows, escalation contacts and out-of-scope assets.
04
Delivery
The person who scoped the work does the work. Critical findings are reported within 24 hours of discovery rather than held for the report.
05
Report, debrief and retest
Written report, technical debrief, optional board briefing, and a free retest of findings within 60 days.
Independence
Why the report is worth something.
Assurance from a party with a commercial interest in the answer is not assurance. Three rules make ours usable.
We do not test what we built
If we designed or deployed a system, we do not review it and call that assurance. Where a client wants both, the review goes to an independent tester we bring in, or the build goes to a partner.
No tooling resale, no vendor commissions
We take no margin on any product we recommend. Remediation guidance is tied to a control objective, not to a partner agreement.
We will tell you when you do not need us
If the honest answer to a scoping call is that your existing controls are adequate, that is the answer you get.
The practitioner
Who does the work.
Every engagement is delivered by Mathew Sayed, a certified offensive and defensive security practitioner with a platform engineering background. The person who scopes the work is the person who runs it and writes the report.
On request
Documents we provide for vendor onboarding.
- ›Current certifications with issuing body and expiry
- ›ABN and entity details for Inline Code Pty Ltd
- ›National Police Check, and Working With Children Check where relevant
- ›Standard engagement terms and data handling position
- ›A sample redacted report, so you can assess the deliverable before you buy it
If your vendor risk process needs something not on this list, ask. It is quicker for both of us than a questionnaire cycle.
AI testing scope
How AI testing is scoped against hosted models.
This is the question that stalls AI testing in procurement, so it is worth answering directly.
We test your integration, data, tools, prompts and identity layer. We do not attack the hosted model itself, and we do not attempt to breach the model vendor's infrastructure. That keeps the engagement inside the vendor's terms of service and inside your contract with them.
It is also where your exploitable risk sits. The model vendor hardens the model. Nobody but you is responsible for what you connected it to, what data you gave it, and what it is permitted to do. That is the surface we test, and it is the surface that produces findings.
The boundary is written into the rules of engagement and the authorisation letter before work begins, so you have a document to show your model vendor if they ask. Full detail is on the methodology page.
Reporting
How findings reach a board, and a regulator.
Three audiences, one engagement
Every report carries a technical section your engineers can act on, an executive summary a non-technical reader can act on, and a one-page position for the board. Written together so they do not contradict each other.
APRA-regulated entities
Findings are mapped to CPS 234 and, where relevant, CPS 230, so the report drops into your existing evidence pack. We do not notify a regulator on your behalf. We give you the material and the timeline so that you can, and we will sit in the conversation if it helps.
Written to be handed to a third party
Reports are structured so you can share them with an auditor, a client's security team or an insurer without rewriting them first.
Data handling
What happens to your data.
- Client data is held only for the duration of the engagement and the agreed retention period afterwards.
- Findings, evidence and reports are stored encrypted, in Australia.
- Credentials issued for testing are returned or revoked at engagement close, and we ask you to rotate them regardless.
- No client data is used to train any model, and no client data is entered into consumer AI tooling.
- Evidence containing personal information is minimised at capture and redacted in the report unless you ask otherwise.
- Sub-processors, where any are used for an engagement, are named in the statement of work before work begins.
Our full position is in the privacy policy and the engagement terms attached to each statement of work.
Procurement
Procurement pack.
Certificates of currency, ABN and entity details, standard engagement terms, data handling position, a sample redacted report, and responses to the vendor risk questionnaires most enterprises use. Sent as a single pack, usually within one business day of asking.
Request the procurement packGet started
Get us on the panel.
A scoping call establishes fit. If your procurement process needs documents first, ask and we will send them before we talk.