About
An independent testing practice for systems you already run.
Sunshield Cyber LLC tests the network, and the AI tools now connected to it. Sunshield Pentest is that work: a clear scope, a careful test, and findings a team can hand to engineering.
How we work
The engagement is the product. We do not sell a scanner seat, a compliance binder, or an open-ended retainer and call it a test. You get a boundary, a window, and a report that says what was true inside that boundary.
Automated tooling is how we cover ground without pretending memory is a methodology. Manual testing is how we decide whether a result is exploitable, noisy, or out of scope. Both stay inside the authorization you sign.
We write for two readers at once. Leadership needs impact in plain language. Engineering needs enough evidence to reproduce the condition and enough direction to fix it. A finding that only one of them can use is unfinished.
Principles
- Scope is a boundary
- If it is not written in, it is not tested. Exclusions are part of the work, not a footnote after the fact.
- Evidence over volume
- A shorter report that changes a decision is better than a long one that documents the scanner.
- Judgment where it counts
- Manual attention goes to the paths that would change access, data, or the action an assistant can take.
- Independence
- Findings are not tied to a product we sell afterward. The recommendation is the fix, not a license.
Authorization comes first.
Sunshield performs security testing only with written permission from the owner of the systems. If you are unsure whether a system is in bounds, that question belongs in the scope, before any testing.