How it works with you

Your client stays your client.

Mutual NDA signed before we discuss the clientbefore scoping
White-label: we work under your brand and your report template, or ours if you preferyour choice
We never contact your client outside the engagement, and won’t solicit them after itnon-solicit
No entry without a signed authorization letter from the site ownersigned
Your rules of engagement, your escalation contacts, your timelineyour terms
A fixed fee per engagement, agreed in writing before we startfixed fee
Send us dates and you get a yes or no within one business day1 business day

Calibre is founder-led, so the person on the scoping call is the person who shows up on site. If an engagement needs more people, they are named and introduced to you before they attend.

Tell us about the engagement

We reply within one business day. A mutual NDA comes before any client detail.

Nothing you send is shared or used to contact your client.

Who we work with

Firms that own the network, not the door.

Penetration testing firms

Your client asked for a physical or social engineering test alongside the network work. We deliver it under your rules of engagement and in your report.

MSSPs and MSPs

A client has a badge problem, a tailgating problem or an audit finding on physical access, and nobody on your bench owns the door.

vCISOs and audit-readiness firms

SOC 2, ISO 27001, PCI DSS, HIPAA and CMMC all carry physical controls. We test them and hand you evidence mapped to the control IDs.

We don’t subcontract to access control integrators or hardware resellers. We take no referral fee or commission on anything we recommend, and that only means something if we stay independent of the people selling it.

What we deliver

Scoped on its own or alongside your work.

Physical penetration testing

Authorized entry attempts against perimeter, lobby, loading dock and restricted areas, day and night, with photographic evidence.

Social engineering

Tailgating, pretexting and impersonation against reception, helpdesk and facilities staff.

Credential & reader testing

What the cards and readers actually are, and whether they clone: 125 kHz prox, MIFARE Classic, DESFire, SEOS.

Access control assessment

Deprovisioning, escort and contractor workflow, anti-passback, cage and cabinet separation, chain of custody.

Compliance physical controls

Testing and evidence for SOC 2 CC6.4, ISO 27001 Annex A.7, PCI DSS Requirement 9, HIPAA §164.310 and CMMC PE.

Remediation guidance

Findings that name the technology to move to and carry a price range, so your client can act on them.

Partners

Have a client asking now?

Send the industry, the number of sites and rough dates. We’ll tell you quickly whether we can take it.