Skip to main content
Delivery models · Where the human sits

Three delivery models, and how to pick one

All three models run the same eleven coverage classes through the same six phases. What changes is who checks the findings, and that is what decides where the assessment can go afterwards.

So start at the far end. Work out what has to happen to the report once it lands, and the model is already chosen.

Start here

Find the row that describes your assessment

Read the left column first. Every one of these is a constraint somebody brought to us, and each one removes options rather than expressing a preference.

What the assessment has to do, and the delivery model that follows
What the assessment has to doThe modelWhat settles it
Go into a regulated filing. Expert verified, or human led Security Brigade signs under its CERT-In empanelment, and the auditor who signs has to have been in the engagement. Both of these models put one there.
Which of the two depends on whether you need the auditor checking the output or running the work.
Cover the estate in the months between deep engagements. Fully autonomous Nobody is waiting on a calendar after scope sign-off, so a run can happen at the cadence your releases actually ship at. The observed median from sign-off to report is one to three business days.
Reach your engineers with findings an auditor has already been through. Autonomous, expert verified A senior auditor verifies every finding before any of it reaches you.
Be an engagement a named senior auditor has run. Human led The auditor sets the scope, directs where the depth goes and owns the report. B-52 does the testing underneath.
You do not know yet. Autonomous, expert verified Take it as the default. Coverage is the same either way, and it leaves the regulated route open if the answer changes after you have started.

What the assessment has to do, and the delivery model that follows

Go into a regulated filing.

The model
Expert verified, or human led
What settles it
Security Brigade signs under its CERT-In empanelment, and the auditor who signs has to have been in the engagement. Both of these models put one there.

Which of the two depends on whether you need the auditor checking the output or running the work.

Cover the estate in the months between deep engagements.

The model
Fully autonomous
What settles it
Nobody is waiting on a calendar after scope sign-off, so a run can happen at the cadence your releases actually ship at. The observed median from sign-off to report is one to three business days.

Reach your engineers with findings an auditor has already been through.

The model
Autonomous, expert verified
What settles it
A senior auditor verifies every finding before any of it reaches you.

Be an engagement a named senior auditor has run.

The model
Human led
What settles it
The auditor sets the scope, directs where the depth goes and owns the report. B-52 does the testing underneath.

You do not know yet.

The model
Autonomous, expert verified
What settles it
Take it as the default. Coverage is the same either way, and it leaves the regulated route open if the answer changes after you have started.

Notice what is missing from that table. Nothing in it turns on what gets tested, because that does not vary — see the next band for what stays fixed no matter which row you land on.

The three models

The three models, side by side

Read the middle column as a position rather than as an amount of help. A senior auditor either verifies the findings, runs the engagement, or is not in it.

The three delivery models and what each one can be signed as
ModelWhere the human sitsWhat Security Brigade can sign
Fully autonomous A person authorises the scope and the targets. Nobody acts after that. Security Brigade cannot sign it under its CERT-In empanelment.
Autonomous, expert verified A senior auditor verifies every finding before any of it reaches you. Security Brigade can sign it under its CERT-In empanelment.
Human led A senior auditor runs the engagement, with B-52 doing the testing underneath. Security Brigade can sign it under its CERT-In empanelment.
Key
  • An empanelled auditor is in the engagement
  • No empanelled auditor is in the engagement

What does not change

The models differ by where the human sits, never by what is tested

Constant in all three

Three things the delivery model has no bearing on

What is tested
Eleven coverage classes, from web and mobile applications through to Active Directory, source code and AI applications. Physical security, hardware and wireless testing sit outside all three models.
How it is tested
Six phases — discovery, planning, scanning, exploitation, reporting, and a QA gate that sits after reporting and can send the finished report back to the phase that produced it.
What a finding carries
A reproducible exploit artefact: the request, the response and the steps to reproduce it. That holds in every model, including the one with nobody in the loop.

The platform underneath is the same one

Security Brigade has been CERT-In empanelled since 2008, and every assessment the firm has run since it started in 2006 is held inside Lemon, our own assessment platform. 6,700+ assessments of test cases, vulnerabilities and threat models are the corpus behind our models, and the B-52 harness runs the practices a Security Brigade auditor runs — mindmap creation, test-case generation, comprehensive JavaScript analysis and functional flow analysis.

None of that is bought or withheld by the tier you pick. The eleven classes go as deep in one model as in the next, down to decompiling and analysing the binary in the mobile class.

What the platform does on a run

For a regulated filing

What our signature rests on

If the assessment is going into a filing, take the expert-verified or the human-led model. The reason is mechanical rather than commercial, and it is worth reading before you scope.

How signability works here
  • CERT-In empanelment attaches to Security Brigade, the firm. B-52 itself holds no certification of its own, and none is claimed for it.
  • A Security Brigade auditor signs the assessment. For that auditor to sign it, the auditor has to have been in the engagement.
  • In the expert-verified model the auditor verifies every finding; in the human-led model the auditor runs the work. Either satisfies that condition.
  • In the fully autonomous model nobody at Security Brigade acts after scope sign-off, so there is no auditor to put a name to it.
  • Security Brigade holds CERT-In empanelment and ISO 27001 certification. Both cover how the work is delivered, not the platform that performs it.