Insurance pays after the damage. The Shield prevents it.
One engagement, built from your modules, proves exactly how your company would be breached. Then the Shield stays on — watching, re-testing and alerting as your business changes. Fixed fee, tailored to your size. No surprises, in either sense.

Three moves. No surprises.
Built from modules. Each at 100%.
You pick the attack paths worth testing — that's your engagement. Whatever you activate runs in full: we never sell a partial look at a module. Add one later and it starts with its own first engagement, then joins the Shield.
One breach outspends a decade of Shield.
No scare copy — just the public numbers behind the laws you answer to and the incidents that hit companies your size every week.
Swiss data-protection law now fines the responsible person, not just the company. Criminal — and it follows you.
Invoicing frozen, staff idle, customers quietly finding alternatives. Recovery is measured in weeks — if backups held.
One EU customer is enough. The EU rulebook stacks on top of Swiss law — and it fines revenue, not profit.
One line in the budget, agreed in writing before we start. Configure yours below in two minutes.
PRICE IT NOW ↓Why the Shield holds.
Every finding crosses four verification gates. If it reaches you, it's real — your IT never chases ghosts.
Four weeks of crew work, delivered in one — everything active at once. You pay for judgment by the day, not a crew by the month.
Every report is PGP-signed and verifies against our published key at qsearch.ch/pgp-key.asc. If a single byte changes, verification fails. Your auditor and insurer can check it themselves.
You get risk in francs and legal duties. Your IT gets traces and fixes. Same signed document.
One subscription. Built from your modules.
Your Shield keeps permanent watch on the same modules as your First Engagement — those, no more, no less. Add, drop or swap modules mid-subscription as the business evolves (a new module starts with its own first engagement), and retune the cadence anytime. A full re-assessment is included every 4 months; step it up to monthly or weekly. The continuous check runs daily by default — tune it down to weekly sweeps or up to second-by-second.
For scale: external IT support for an 8-person Swiss firm runs CHF 50–80k a year. The Shield is built to sit well under what you already pay to keep the lights on.
Could someone get in…
CLICK TO TOGGLE · WHITE- OR BLACK-BOX, PER MODULEStanding deep-dive on the product your customers touch — beyond the first pass.
Inside your AWS, Azure or GCP: permissions drift, exposed keys, forgotten services — continuously.
Phishing and pretexting, run safely — also available standalone with awareness training.
Segmentation, VPN, wireless — the paths between your systems.
We start inside — and measure how far a single compromised device gets.
Vendors, dependencies and integrations as a way into you.
Prompt injection, data leakage, runaway agents — tested before someone else does.
AI-generated auth, validation and dependencies — checked for inherited flaws.
Your own product, reviewed the way an attacker reads it — code to runtime.
…and beyond red, on request.
FLAG IT HERE — IT RIDES ALONG IN YOUR DRAFTWe work alongside your existing IT — internal or external. They keep things running; we prove it's safe. No overlap, no turf war, no pressure to switch providers. When you want more than proof, flag the blue side — through us and vetted partners, scoped separately from the calculator.
We run the offense live while your IT tunes detection and response in real time — findings become muscle memory, not a PDF.
Standalone or after a social-engineering round: sessions built on the exact e-mails and calls that would have fooled your team.
Shield monitoring wired into a 24/7 alert pipeline — run with vetted partners, or plugged into the provider you already have.
Day-to-day IT run — or hardware bought right — through vetted partners, coordinated with the security picture. Only if you ask.
Your Shield, in numbers.
EVERYTHING YOU TOGGLED, PRICED LIVE — INDICATIVE BY DESIGNThe questions executives actually ask.
Then you get signed evidence of exactly that — what we tested, how deep, and what held. Your auditor, your insurer and your board can verify it. Either way, the Shield keeps checking as things change.
No. Every engagement runs under a written scope ruling and our reconnaissance policy — engineered to prove impact without causing it. Anything intrusive is agreed first, in writing.
Keep them — we're not a replacement. They run your systems; we independently verify them. Findings arrive as fix-ready traces your provider can act on, and we retest their fixes at no extra cost.
Attacks are automated — they don't check your headcount. Small firms get hit precisely because attackers assume nobody is watching. The Shield makes that assumption wrong.
Yes — quarterly, no lock-in. Everything we produced stays yours: reports, evidence, fixes. If you come back later, your history comes back with you.
There's no exit fee and no clawback on anything you've already fixed. We close out with a final signed report and a clean export of every finding — plus a short handover note your own IT or next provider can pick up cold.
By the modules you activate — each priced for your size, white- or black-box, sharing one platform core (every module after the first: −25%) — and the cadence you choose; daily check and 4-month re-assessment come with every subscription. Add, drop or swap modules mid-subscription; a new module starts with its own first engagement. All nine together earn −10%. Always fixed before we start, in writing. Never per finding, never an "urgent" upsell.
White box tests with knowledge — accounts, architecture, source — so the whole budget goes into depth. Black box starts blind, like a real outsider: maximum realism, more budget burned on discovery, priced +20–45% by module. Most companies mix — black-box what the internet sees, white-box what's behind the login. The calculator above prices both.
Red attacks, blue defends. The Shield is red: we prove how you'd be breached before someone else does. Blue is detection, response, training and operations — available as extra modules above, with vetted partners. Purple is both at one table: we attack live while your IT tunes the defenses.
Swiss market, 2026: CHF 8–15k for a web-application test, CHF 10–25k for infrastructure, CHF 8–18k for mobile or APIs; a full multi-week crew assessment at CHF 700/hour lands at CHF 84–126k. QSearch modules start at the low end of those ranges, and every module after the first costs −25% — recon and reporting run once. Fixed in writing, and the engagement doesn't end: the Shield keeps watching and re-testing all year.
Attackers don't wait for your annual audit. After one complete engagement, continuous coverage — daily checks plus a big re-assessment every 4 months — keeps pace with every deploy, hire and new CVE. That's exactly what the Shield is.
Every shield is tailored. Every fee is fixed.
One conversation — scoped to your business, not a product catalog. If we're not the right fit, we'll tell you.
