Our Approach
How AishiSec Works
Security testing is only as good as the process behind it. Everything AishiSec does follows one structure: understand what matters to your business, test it the way an attacker would, and report in a way your business can act on.
This page exists so you can see the working method before you commit to anything: what we test, how we classify what we find, what evidence looks like, and what happens after the report is delivered.
The Process
Seven steps, from your requirements to a verified fix.
Understand
Understand the application, business and testing requirements.
Scope
Define exactly what can and cannot be tested.
Test
Perform manual and automated security testing.
Validate
Verify vulnerabilities and safely demonstrate their impact.
Report
Provide clear technical and business-focused findings.
Remediate
Help the client understand how weaknesses can be addressed.
Retest
Verify whether identified issues have been resolved.
And the cycle repeats as your application changes.
Standards We Work With
AishiSec's testing follows two widely recognised frameworks: OWASP and MITRE ATT&CK. They serve different jobs. One describes weaknesses, the other describes how real attackers operate.
OWASP (the Open Worldwide Application Security Project) publishes the de-facto reference lists of application weaknesses. Our application, API, mobile, source-code and AI assessments are structured around the relevant OWASP projects: the Web Application Security Testing Guide, the API Security Top 10, the Mobile Application Security Verification Standard and the LLM Top 10.
MITRE ATT&CK is the public knowledge base of real attacker techniques and tactics. Our network, cloud, Wi-Fi and red team work maps findings to ATT&CK techniques, so your team can see exactly which real-world attack patterns apply, and what to monitor for.
If your audit or compliance process asks for a specific standard, tell us, and we'll confirm how our testing maps to it before we start.
How We Classify Findings
Every finding is rated twice: a technical severity, for the engineers who fix it, and a business impact, for the people who decide what to fix first.
Critical / High
Exploitable weaknesses that can directly compromise data, accounts or systems. These need attention first.
Medium
Weaknesses that require specific conditions but still represent real risk, and should be fixed in the near term.
Low / Informational
Hardening opportunities and observations that don't enable a direct attack but are worth addressing.
Evidence & Verification
Automated tools report signals. Our testers verify each one by hand, confirming the weakness is real, understanding what an attacker could actually achieve, and removing false positives before they reach your report.
Each confirmed finding carries the steps to reproduce it and the evidence behind it, so your team can verify our work independently, and your auditors can too.
What the Report Contains
One report, two audiences: the summary your leadership reads, and the detail your developers fix from.
- Executive summary: what we found and what it means, written for decision-makers
- Detailed findings: what is wrong, why it matters, what an attacker could do, how to fix it
- Evidence: how each finding was reproduced
- Risk ratings: technical severity and business impact, side by side
- Remediation guidance: practical steps your developers can act on
- Retest results: verification after fixes, when included
Retesting After Remediation
A report is the midpoint, not the end. After your team fixes the findings, we retest the same areas to verify the fixes actually close the issues, and confirm nothing else opened in the process.
The retest result is documented alongside the original finding, so the record shows the full story: found, fixed, verified.
Scope & Rules of Engagement
Every assessment runs inside an agreed scope: what will be tested, when, and what is off limits. Nothing is tested without written authorization from the system's owner. Everything found stays confidential between AishiSec and you.
If you have questions about how we work, or want to know whether our approach fits a specific standard or audit requirement, ask us. A real answer beats a checkbox.
Know where your security stands.
Tell us what you're building, operating or protecting. We'll help you determine where security testing should start.

