~/appsecaudit/process.txt

Process

From first call to verified fixes.

  1. CALL
  2. SCOPE
  3. SIGN
  4. TEST
  5. DELIVER
  6. RE-TEST

0x01 / CALL

Start with context.

A short call establishes the application, objective, and constraints.

0x02 / SCOPE

Keep the target focused.

Define clear boundaries, access, prerequisites, and expected effort.

0x03 / AGREE

Remove ambiguity.

Confirm the scope and schedule, then sign the contract and NDA.

0x04 / TEST

Attack the real system.

Manual testing verifies, reproduces, and documents meaningful attack paths.

0x05 / DELIVER

Make findings usable.

Evidence, impact, and remediation arrive in formats engineers can act on.

0x06 / RE-TEST

Verify the fixes.

A focused follow-up can validate remediation now or in a later assessment.

// OUTPUT

PDF
Complete report for review and distribution.
MARKDOWN
Portable report source without platform lock-in.
FINDINGS
Individual Markdown files ready for Jira or other issue trackers.
REVISIONS
Internal, auditor, customer-facing, or redacted editions.