Penetration testing firms
Your client asked for a physical or social engineering test alongside the network work. We deliver it under your rules of engagement and in your report.
Calibre delivers physical penetration testing, social engineering and access control assessment for pentest firms, MSSPs and vCISOs. White-label or under our name, under your rules of engagement, written into your report.
Calibre is founder-led, so the person on the scoping call is the person who shows up on site. If an engagement needs more people, they are named and introduced to you before they attend.
We reply within one business day. A mutual NDA comes before any client detail.
Nothing you send is shared or used to contact your client.
Your client asked for a physical or social engineering test alongside the network work. We deliver it under your rules of engagement and in your report.
A client has a badge problem, a tailgating problem or an audit finding on physical access, and nobody on your bench owns the door.
SOC 2, ISO 27001, PCI DSS, HIPAA and CMMC all carry physical controls. We test them and hand you evidence mapped to the control IDs.
We don’t subcontract to access control integrators or hardware resellers. We take no referral fee or commission on anything we recommend, and that only means something if we stay independent of the people selling it.
Authorized entry attempts against perimeter, lobby, loading dock and restricted areas, day and night, with photographic evidence.
Tailgating, pretexting and impersonation against reception, helpdesk and facilities staff.
What the cards and readers actually are, and whether they clone: 125 kHz prox, MIFARE Classic, DESFire, SEOS.
Deprovisioning, escort and contractor workflow, anti-passback, cage and cabinet separation, chain of custody.
Testing and evidence for SOC 2 CC6.4, ISO 27001 Annex A.7, PCI DSS Requirement 9, HIPAA §164.310 and CMMC PE.
Findings that name the technology to move to and carry a price range, so your client can act on them.