Skip to main content
QSearch Security ResearchQSearch Security ResearchENGINEERED CONTINUOUS ADVERSARIAL INTELLIGENCE
SERVICES — CONTINUOUS PROTECTION, VERIFIED

Insurance pays after the damage. The Shield prevents it.

One engagement, built from your modules, proves exactly how your company would be breached. Then the Shield stays on — watching, re-testing and alerting as your business changes. Fixed fee, tailored to your size. No surprises, in either sense.

Fixed fee — never per-finding PGP-signed reports Swiss-registeredWHAT IT COSTS ↓
Protective aurora arc over small structures
SHIELD EVENT — TODAY, 09:41AUTO-HANDLED ✓
New subdomain deployed by your team → tested within the hour
SURFACE +1RE-TEST PASSED ✓NO ACTION NEEDED
SHIELD STATUS — LIVE
monitoring · active ✓   ·   last re-test · 3 days ago ✓   ·   open criticals · 0   ·   next big re-assessment · 12 days   ·   new CVEs checked against your stack today · 114   ·   monitoring · active ✓   ·   last re-test · 3 days ago ✓   ·   open criticals · 0   ·   next big re-assessment · 12 days   ·   new CVEs checked against your stack today · 114   ·   
what every Shield customer sees
HOW IT WORKS

Three moves. No surprises.

STEP 02 — THE FIRST ENGAGEMENT

Built from modules. Each at 100%.

You pick the attack paths worth testing — that's your engagement. Whatever you activate runs in full: we never sell a partial look at a module. Add one later and it starts with its own first engagement, then joins the Shield.

Recon first — your surface mapped before we strike
Every way in tried — like a real attacker
Every module you activate, run to 100%
Every finding proven — four gates, zero theory
One signed report: francs for you, fixes for IT
Free retest after you fix
BUILD IT FROM THE MODULES BELOW:+ CLOUD+ AI / LLM+ SOCIAL ENG.…full list below
The fee is fixed before we start — the sum of your modules, priced for the size and complexity of your environment. Never billed per finding. The deliverable is yours whether or not you continue to the Shield.
THE COMPARISON — SAME ASSESSMENT, TWO WAYSSWISS MARKET RATES · 2026
OLD SCHOOL3 consultants on site
1× senior + 2× juniorbilled by the hour
4–6 weeks on site20–30 days
coverage after deliverynone
CHF 84–126kONE SNAPSHOT · STALE IN MONTHS
VS
QSEARCH1× team · platform + research
1× team, everything active at once≤ 1 week
scope and feefixed up front
coverage after deliverycontinuous
Fixed fee, tailoredQUOTED BEFORE WE START ✓
THE 200× COMPRESSES THE MECHANICAL WORK — NOT THE INVOICE. YOU PAY JUDGMENT FOR DAYS, NOT A CREW FOR WEEKS.
THE COST OF DOING NOTHING

One breach outspends a decade of Shield.

No scare copy — just the public numbers behind the laws you answer to and the incidents that hit companies your size every week.

CHF 250'000
PERSONAL FINE — REVISED FADP

Swiss data-protection law now fines the responsible person, not just the company. Criminal — and it follows you.

3–4 weeks
TYPICAL RANSOMWARE DOWNTIME

Invoicing frozen, staff idle, customers quietly finding alternatives. Recovery is measured in weeks — if backups held.

4% of turnover
GDPR — IF YOU TOUCH THE EU

One EU customer is enough. The EU rulebook stacks on top of Swiss law — and it fines revenue, not profit.

Fixed & known
THE SHIELD — PER YEAR

One line in the budget, agreed in writing before we start. The entry figure is published below.

WHAT IT COSTS ↓
SOURCES: REVISED FADP ART. 60–63 · GDPR ART. 83 · RANSOMWARE RECOVERY MEDIANS, INDUSTRY INCIDENT DATA 2024–2026
PROOF OVER PROMISES

Why the Shield holds.

01
Zero false positives

Every finding crosses four verification gates. If it reaches you, it's real — your IT never chases ghosts.

EXPLOITEDVERIFIEDCHALLENGEDAUDITED
02
200× compression

Four weeks of crew work, delivered in one — everything active at once. You pay for judgment by the day, not a crew by the month.

03
Cryptographically signed

Every report is PGP-signed and verifies against our published key at qsearch.ch/pgp-key.asc. If a single byte changes, verification fails. Your auditor and insurer can check it themselves.

04
One report, two readers

You get risk in francs and legal duties. Your IT gets traces and fixes. Same signed document.

THE RECEIPTS10+ REDACTED CASES100+ VERIFIED FINDINGS0 FALSE POSITIVESSEE THE TRACK RECORD →
STEP 03 — THE SHIELD

One subscription. Built from your modules.

Your Shield keeps permanent watch on the same modules as your First Engagement — those, no more, no less. Add, drop or swap modules mid-subscription as the business evolves (a new module starts with its own first engagement), and retune the cadence anytime. A full re-assessment is included every 4 months; step it up to monthly or weekly. The continuous check runs daily by default — tune it down to weekly sweeps or up to second-by-second.

For scale: external IT support for an 8-person Swiss firm runs CHF 50–80k a year. The Shield is built to sit well under what you already pay to keep the lights on.

Always in every ShieldALWAYS ON, ANY MODULE MIX
Continuous check — daily
Re-test of every fix you ship
Full re-assessment every 4 months
Direct line to the researcher
WHAT IT WATCHES FOR IS YOURS TO PICK — NINE SHIELD MODULES BELOW ↓

Re-tests and the 4-month re-assessment run on exactly the modules you activated in your First Engagement — those, no more, no less. Add a module later and it joins after its own first engagement.

SCOPED ON THE PERIMETER UNDER WATCH — AGREED WITH YOU, FIXED IN WRITING BEFORE WE START
01

The First Engagement

NINE MODULES, PICK THE ATTACK PATHS WORTH TESTING · EVERY MODULE RUNS TO 100%, SUB-MODULES INCLUDED

APPLICATION
…through your website or app?

Standing deep-dive on the product your customers touch. Beyond the first pass, and kept up as you ship.

CLOUD
…through your cloud setup?

Inside your AWS, Azure or GCP: permissions drift, exposed keys, forgotten services.

SOCIAL ENGINEERING
…by fooling one of your people?

Phishing and pretexting, run safely. Also available standalone with awareness training.

NETWORK
…through your network or Wi-Fi?

Segmentation, VPN, wireless. The paths between your systems, and the machines nobody patches.

ASSUMED BREACH
…from one infected laptop?

We start inside, and measure how far a single compromised device or account gets.

SUPPLY CHAIN
…through one of your suppliers?

Vendors, dependencies and integrations as a way into you.

AI / LLM
…through your AI features?

Prompt injection, data leakage, runaway agents. Tested before someone else does.

VIBE-CODING
…through code AI wrote for you?

AI-generated auth, validation and dependencies, checked for inherited flaws.

SOFTWARE
…through the software you ship?

Your own product, reviewed the way an attacker reads it. Code to runtime.

02

The Shield Watch

NINE MODULES, PICK WHAT IT WATCHES FOR · SUB-MODULES INCLUDED

CVE & EXPLOIT WATCH
New holes, checked against your stack.

Every new vulnerability and public exploit, matched to the software you actually run.

CREDENTIAL & DATA LEAKS
Your passwords and data, found before they are used.

Breach dumps, stealer logs, documents and source that surfaced in the open.

ATTACK SURFACE (EXT.)
What the internet sees, as it changes.

New subdomains, exposed services and certificates, tested within the day.

ATTACK SURFACE (INT.)
What appears inside your walls.

New devices, shares and services showing up on your own network.

CLEARNET + DARK WEB
Who is talking about you, and where.

Mentions, access for sale, and the groups working on your sector.

DOMAIN & BRAND ABUSE
Your name, used against your customers.

Lookalike domains, phishing kits, and mail records that drift.

PEOPLE — TRAINING & AWARENESS
Your people, kept sharp.

Recurring simulations and short sessions, built on the lures that would work.

CLOUD & SAAS POSTURE
Settings that drift, caught early.

Permission drift, new public storage, keys in the wrong place.

SUPPLIERS & INTEGRATIONS
Your suppliers, watched like your own.

Breaches and exposures at the vendors who hold your data or your access.

Also available, on request

SCOPED SEPARATELY, NEVER BUNDLED INTO THE SHIELD FEE

PURPLE TEAM
Attack and defense, one table.

We run the offense live while your IT tunes detection and response in real time.

AWARENESS TRAINING
Your people, trained on real lures.

Sessions built on the exact e-mails and calls that would have fooled your team.

SOC-LITE / ALERTING 24/7
Someone watching, around the clock.

Shield monitoring wired into a 24/7 alert pipeline.

MANAGED IT & HARDWARE
IT and hardware, security-first.

Day-to-day IT run, or hardware bought right, through vetted partners.

RANSOMWARE READINESS
The bad day, rehearsed.

Backups restored for real, segmentation checked, a playbook your team has run.

AUTOMATIONS & DEVOPS
Security on rails, on every deploy.

Onboarding, patch windows and pipelines wired so the routine happens without anyone remembering.

WEB & MARKETING MANAGEMENT
Your site, run by people who test it.

Hardened CMS, clean DNS, campaigns tracked without leaking customer data.

COMPLIANCE EVIDENCE
Questionnaires answered from signed proof.

nFADP, GDPR, ISO 27001 or NIS2 asks, answered with the reports you already hold.

VENDOR SECURITY REVIEW
Read their claims like an attacker would.

Suppliers checked before you sign, not after the breach.

WHAT IT COSTS

Two figures, so you know the order of magnitude before you call.

Both are entry figures for the smallest sensible scope, not quotes. What you actually pay depends on the modules you activate and the size of the environment behind them — and it is fixed in writing before any testing starts. Never billed per finding.

ONE-OFF · THE FIRST ENGAGEMENT
Secure it
from CHF 4'000.—

We test, you fix, we re-test — the full loop, closed inside less than a working week rather than the four to six on-site weeks a traditional crew books. You keep the signed report either way.

BUILT FROM THE NINE MODULES ABOVE — EVERY MODULE RUNS TO 100%, SUB-MODULES INCLUDED
BUILD YOUR SCOPE →
SUBSCRIPTION · THE SHIELD
Keep it secure
from CHF 1'000.—/month
agreed perimeter.

Priced on the infrastructure actually under watch, agreed with you and reviewed as the perimeter moves. Quarterly exit, no lock-in.

ALWAYS INCLUDED: DAILY CHECK · RE-TEST OF EVERY FIX · RE-ASSESSMENT EVERY 4 MONTHS — ON THE MODULES OF YOUR FIRST ENGAGEMENT
BUILD YOUR SCOPE →
Why we don't leave this to a call: you should be able to tell whether we are in your budget without spending an hour to find out. What a call settles is scope — which paths are worth testing — and that is the only thing the final figure depends on.
A MEASURED ATTACK SURFACE HAS A DATE. A CONFIGURATION THAT IS CORRECT TODAY MAY NOT BE IN TWO WEEKS — A VERSION CHANGES, A SERVICE GETS EXPOSED, AN EXPLOIT LANDS FOR SOMETHING THAT WAS HARMLESS YESTERDAY. THAT IS WHY THE SHIELD KEEPS LOOKING.
STRAIGHT ANSWERS

The questions executives actually ask.

QWhat if you find nothing?

Then you get signed evidence of exactly that — what we tested, how deep, and what held. Your auditor, your insurer and your board can verify it. Either way, the Shield keeps checking as things change.

QWill the testing break something?

No. Every engagement runs under a written scope ruling and our reconnaissance policy — engineered to prove impact without causing it. Anything intrusive is agreed first, in writing.

QWe already have an IT provider.

Keep them — we're not a replacement. They run your systems; we independently verify them. Findings arrive as fix-ready traces your provider can act on, and we retest their fixes at no extra cost.

QAren't we too small to be a target?

Attacks are automated — they don't check your headcount. Small firms get hit precisely because attackers assume nobody is watching. The Shield makes that assumption wrong.

QCan we stop the subscription?

Yes — quarterly, no lock-in. Everything we produced stays yours: reports, evidence, fixes. If you come back later, your history comes back with you.

There's no exit fee and no clawback on anything you've already fixed. We close out with a final signed report and a clean export of every finding — plus a short handover note your own IT or next provider can pick up cold.

QHow is the fee set?

By the scope — which modules you activate, and the size of the environment behind them. The first engagement starts at CHF 4'000.— and the Shield at CHF 1'000.— a month on a perimeter we agree with you; daily check and 4-month re-assessment come with every subscription. Add, drop or swap modules mid-subscription; a new module starts with its own first engagement. Always fixed before we start, in writing. Never per finding, never an "urgent" upsell.

We don't publish an hourly rate. Hours are our problem, not yours: what you are buying is a scope and a signed result, and a rate would only invite a negotiation about how long it took us.

QWhite box or black box — which penetration test do we need?

White box tests with knowledge — accounts, architecture, source — so the whole budget goes into depth. Black box starts blind, like a real outsider: maximum realism, but more of the effort goes into discovery before any testing begins. Most companies mix — black-box what the internet sees, white-box what's behind the login. We settle which is which when we scope, and it is part of the fixed fee either way.

QRed team, blue team — what's the difference?

Red attacks, blue defends. The Shield is red: we prove how you'd be breached before someone else does. Blue is detection, response, training and operations — available on request with vetted partners, scoped separately. Purple is both at one table: we attack live while your IT tunes the defenses.

QHow much does a penetration test cost in Switzerland?

Swiss market, 2026: CHF 8–15k for a web-application test, CHF 10–25k for infrastructure, CHF 8–18k for mobile or APIs; a full multi-week crew assessment lands at CHF 84–126k. Our first engagement starts at CHF 4'000.—, because recon and reporting run once across everything you activate rather than once per test. Fixed in writing, and the engagement doesn't end: the Shield keeps watching and re-testing all year.

QHow often should a company test its security?

Attackers don't wait for your annual audit. After one complete engagement, continuous coverage — daily checks plus a big re-assessment every 4 months — keeps pace with every deploy, hire and new CVE. That's exactly what the Shield is.

MORE QUESTIONS? A RESEARCHER ANSWERS THEM ON THE CALL — NOT A SALES TEAM

Every shield is tailored. Every fee is fixed.

One conversation — scoped to your business, not a product catalog. If we're not the right fit, we'll tell you.