Security and procurement
Answers to the questions security and procurement teams ask when onboarding a testing vendor. If something you need isn’t here, email chris@hacknow.com.
Company
- Legal name
- HackNow, LLC, a Texas limited liability company.
- Founded
- 2023. Based in Austin, Texas.
- NAICS codes
- 541512, 541519, 541690.
- Contact
- chris@hacknow.com. We reply to every request within one business day.
Documents
- W-9
- On request.
- Non-disclosure agreement
- We’ll sign a mutual NDA before scoping, or send ours.
- Sample report
- A sample report is available on request under NDA. Ask for it See the example report, built on a fictional company
People
- Who tests
- All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.
- Certifications
- Certifications held across our testing team include OSCP, CRTO, CISSP, CCSK, and AWS Certified Solutions Architect – Associate.
- Experience
- Our testers have delivered 100+ penetration tests over their careers, including engagements for partner security firms.
Your data
- Evidence handled under your contract
- Evidence is kept and deleted under the confidentiality and retention terms in your contract.
- Minimal data access
- We access sensitive data only as far as needed to prove impact.
- Default retention
- If your contract doesn’t set a period, we keep evidence for one year after the final report, then delete it.
- Where it’s stored
- Google Workspace (Google Drive), encrypted at rest, with multi-factor authentication on every account that can reach it.
- If something goes wrong
- If a HackNow system holding your data is compromised, we notify your named contacts within 24 hours of confirming it.
- Website data
- Information sent through this website is covered by our privacy policy. Privacy policy
Contracts
- Business associate agreements
- We sign a business associate agreement (BAA) when you need one.
Commitments
- Reply within one business day
- We reply to every request within one business day.
- Critical findings within 24 hours of confirmation
- Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report within 5 business days
- Final report delivered within 5 business days after testing ends.
- One retest included
- One retest of reported findings within 90 days of the final report, included in the price.
- Our own US-based testers
- All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.
- Fixed fee
- Every engagement is a fixed fee after a free scoping call.
Engagement commitments apply to work under a signed HackNow proposal.
Testing safety
- Written authorization first
- Signed rules of engagement define exactly what we can and cannot touch.
- Known testing windows and source IPs
- Your named contacts always know when we’re testing and where traffic comes from.
- Emergency contacts on both sides
- We agree on emergency contacts on both sides before we start, and you can pause testing at any time with one message.
- Nothing destructive without approval
- No denial-of-service or destructive testing without written approval.
Our site
A security firm’s own website should pass the checks it would run on yours.
- Cookies
- This site sets no cookies of its own.
- Scripts
- No trackers. No analytics scripts. No third-party scripts.
- Browser security
- Every page is served with a strict Content-Security-Policy and HSTS.
- Vulnerability disclosure
- Read our disclosure policy
- Check it yourself
- See our live Mozilla HTTP Observatory result
Comparing us with your current provider?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.