Name Your Price: OSINT Assessment
Custom OSINT assessment service where clients can define their needs and budget, allowing for a flexible and tailored open-source intelligence project.
In scope
- Flexible OSINT research
- Customizable deliverables
- Budget-aligned services
- Client-specified focus areas
You receive
- Custom OSINT Report
- Client-defined outputs
Tiers
Choose the depth.
Custom OSINT Service
Scoped
Buyer states the focus areas and budget; a written scope fixes the analyst hours, sources and deliverable before work starts. Passive open-source research only, by one OSINT consultant. No fixed cap - every limit is set at scoping.
- Scoping call and written scope statement
- Passive open-source research on client-specified focus areas
- Custom OSINT report in the agreed format
- Hours and deliverables matched to the agreed budget
- — Active scanning, social engineering or any intrusive testing
- — Work outside the written scope statement
- — Ongoing monitoring unless written into the scope
Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.
What's inside this engagement
Phase by phase.
How a security assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.
01Scoping
Systems, sites, stakeholders and the question the assessment must answer.
You see · Your objectives and constraints.
02Discovery & evidence
Documents, configurations and interviews, plus technical testing where the service includes it.
You see · Access and time with key people.
03Analysis
Findings rated by risk to your business, not by a generic score.
You see · A prioritized view of your risk.
04Report & debrief
Executive summary, findings and a remediation roadmap, walked through with your team.
You see · The report and the debrief.
Commercials
From first call to final report.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Related
Dark Web & Credential Exposure Monitoring
Stolen credentials and infostealer logs are the most common way in. We monitor breach corpuses, infostealer markets, paste sites and criminal forums for your domains, executives and key vendors, validate what we find, and tell you what to reset and why — analyst-reviewed alerts rather than a raw feed.
Domain Profiler (OSINT) External
Domain Profiler (OSINT) - External is a tool that provides a comprehensive footprint analysis of your domain, identifying exposed data and vulnerabilities across multiple public sources.
Healthcare & University OSINT Assessment
Sector-specific OSINT assessment focused on healthcare institutions and universities, providing exposure analysis and external threat mapping.
Research
Latest from the blog

compliance · Sep 12, 2026
The EU AI Act's Hidden Breach Clock: Why Article 73 Needs Its Own Line in Your IR Runbook
Article 73 of the EU AI Act imposes a 2/10/15-day serious-incident reporting clock that survived the Digital Omnibus's delay of the rest of the high-risk regime, and it does not map cleanly onto GDPR, CRA or NIS2 deadlines.

cloud-security · Sep 6, 2026
GPUThor and the Unpatchable Layer: When Your AI Infrastructure Risk Is Silicon, Not Software
University of Toronto researchers demonstrated a Rowhammer attack that defeats on-die ECC on NVIDIA workstation GPUs and reaches host root in about 1.1 minutes, down from roughly 22 hours. No software patch is possible, and the proof of concept is scheduled for November 15. Paired with NVIDIA's NemoClaw DNS-rebinding flaw, it defines the hardware boundary of AI infrastructure risk.

ai-security · Sep 5, 2026
Excessive Agency Moved to #3: What the 2026 OWASP LLM Top 10 and the Agent Control Standard Change For Your Program
The OWASP GenAI Security Project's 2026 list weighted 6,639 real incidents against expert consensus, and the largest movement on it was Excessive Agency climbing from #6 to #3. Alongside it shipped the Agent Control Standard v0.1, which defines agent governance through OpenTelemetry and OCSF tracing. The ranking is a lagging indicator finally catching up to what is actually breaking.
Start an engagement