Piscium SecurityPISCIUMSECURITY
Managed Evaluation

Start with a run, not a rollout.

A managed Radius run, delivered by our team against a scope you authorize. Fixed scope, fixed price, re-validation included, and reporting built to survive being handed to someone who was not in the room.

What it is

Scope and price
Agreed and closed before the engagement starts.
Re-validation
Included. Radius attacks the fixed path again and confirms it is closed.
Duration
Two to four weeks, depending on asset count and whether OT zones are in scope. Credited if you continue to continuous coverage inside the re-validation window.
AI model key
You supply it, or we do. The scope is the same and only the price differs.
Deployment required
None. We run it and you receive the evidence.

What you are left holding

Most testing leaves you with a PDF. This leaves you with evidence.

Executive

Executive report

What was exposed, what it would cost an attacker, and what changed after remediation. Written to be read by people who do not run the tooling.

For the board and the exec team

Technical

Technical report

The validated attack paths themselves: reachability, the chain at each hop, and the evidence captured when a path was proven exploitable.

For your security engineers

Compliance

Compliance report

The same run expressed as control evidence: what was tested, when, under whose authorization, and what the outcome was.

For your auditor and your supervisor

Trail

Safety audit trail

Every action an agent attempted, the decision taken on it, the reason, and a snapshot of the rules of engagement in force at that moment.

For anyone who asks what we did to your environment

Each report exists at three levels (the whole run, a single asset, a single finding), nine documents in all. The compliance report and the safety audit trail are the two artifacts a traditional test does not give you. They are what turn “we ran a test” into something an auditor can accept.

How the engagement runs

Four steps, agreed up front, starting with a 30-minute call. The scarcest thing in this business is permission to touch a production environment, and the whole engagement is built around earning and documenting it.

01

Scope and authorization

We agree the environment in scope, the rules of engagement, the testing window and the price before anything runs. Nothing is tested that you have not authorized in writing.

02

The run

Radius observes the environment, reasons over the attack graph, attacks the paths that matter and validates how far each one got, all inside the rules you signed. A run takes two to four weeks; critical findings are communicated the moment they are validated.

03

Reporting

You receive the executive, technical and compliance reports, each at run, asset and finding level, together with the safety audit trail for the run.

04

Re-attack

After you remediate, Radius attacks the affected paths again and confirms they are closed. Re-validation is included in the engagement, not a second purchase. If you continue to continuous coverage inside the re-validation window, the run is credited.

Scope a run

Tell us what you want assessed. We will come back with a scope, a rules-of-engagement draft and a fixed price before anything runs.

Scope a run