Skip to main content
QSearch logomarkQSearch Security ResearchENGINEERED CONTINUOUS ADVERSARIAL INTELLIGENCE
SERVICES — CONTINUOUS PROTECTION, VERIFIED

Insurance pays after the damage. The Shield prevents it.

One engagement, built from your modules, proves exactly how your company would be breached. Then the Shield stays on — watching, re-testing and alerting as your business changes. Fixed fee, tailored to your size. No surprises, in either sense.

Fixed fee — never per-finding PGP-signed reports Swiss-registeredLAUNCH OFFER — NEW CLIENTS · LAST 8 SLOTS · SEE IT PRICED ↓
Protective aurora arc over small structures
SHIELD EVENT — TODAY, 09:41AUTO-HANDLED ✓
New subdomain deployed by your team → tested within the hour
SURFACE +1RE-TEST PASSED ✓NO ACTION NEEDED
SHIELD STATUS — LIVE
monitoring · active ✓   ·   last re-test · 3 days ago ✓   ·   open criticals · 0   ·   next big re-assessment · 12 days   ·   new CVEs checked against your stack today · 114   ·   monitoring · active ✓   ·   last re-test · 3 days ago ✓   ·   open criticals · 0   ·   next big re-assessment · 12 days   ·   new CVEs checked against your stack today · 114   ·   
what every Shield customer sees
HOW IT WORKS

Three moves. No surprises.

STEP 02 — THE FIRST ENGAGEMENT

Built from modules. Each at 100%.

You pick the attack paths worth testing — that's your engagement. Whatever you activate runs in full: we never sell a partial look at a module. Add one later and it starts with its own first engagement, then joins the Shield.

Recon first — your surface mapped before we strike
Every way in tried — like a real attacker
Every module you activate, run to 100%
Every finding proven — four gates, zero theory
One signed report: francs for you, fixes for IT
Free retest after you fix
BUILD IT FROM THE MODULES BELOW:+ CLOUD+ AI / LLM+ SOCIAL ENG.…full list below
The fee is fixed before we start — the sum of your modules, priced for the size and complexity of your environment. Never billed per finding. The deliverable is yours whether or not you continue to the Shield.
THE MATH — SAME ASSESSMENT, TWO WAYSSWISS MARKET RATES · 2026
OLD SCHOOL3 consultants on site
1× seniorCHF 400/h
2× juniorCHF 300/h
crew rate × 6h/dayCHF 4'200/day
4–6 weeks on site20–30 days
CHF 84–126kONE SNAPSHOT · STALE IN MONTHS
VS
QSEARCH1× team · platform + research
same rate, business-orientedCHF 300–500/h
everything active at once≤ 1 week
coverage after deliverycontinuous
Fixed fee, tailoredQUOTED BEFORE WE START ✓
THE 200× COMPRESSES THE MECHANICAL WORK — NOT THE INVOICE. YOU PAY JUDGMENT FOR DAYS, NOT A CREW FOR WEEKS.
THE COST OF DOING NOTHING

One breach outspends a decade of Shield.

No scare copy — just the public numbers behind the laws you answer to and the incidents that hit companies your size every week.

CHF 250'000
PERSONAL FINE — REVISED FADP

Swiss data-protection law now fines the responsible person, not just the company. Criminal — and it follows you.

3–4 weeks
TYPICAL RANSOMWARE DOWNTIME

Invoicing frozen, staff idle, customers quietly finding alternatives. Recovery is measured in weeks — if backups held.

4% of turnover
GDPR — IF YOU TOUCH THE EU

One EU customer is enough. The EU rulebook stacks on top of Swiss law — and it fines revenue, not profit.

Fixed & known
THE SHIELD — PER YEAR

One line in the budget, agreed in writing before we start. Configure yours below in two minutes.

PRICE IT NOW ↓
SOURCES: REVISED FADP ART. 60–63 · GDPR ART. 83 · RANSOMWARE RECOVERY MEDIANS, INDUSTRY INCIDENT DATA 2024–2026
PROOF OVER PROMISES

Why the Shield holds.

01
Zero false positives

Every finding crosses four verification gates. If it reaches you, it's real — your IT never chases ghosts.

EXPLOITEDVERIFIEDCHALLENGEDAUDITED
02
200× compression

Four weeks of crew work, delivered in one — everything active at once. You pay for judgment by the day, not a crew by the month.

03
Cryptographically signed

Every report is PGP-signed and verifies against our published key at qsearch.ch/pgp-key.asc. If a single byte changes, verification fails. Your auditor and insurer can check it themselves.

04
One report, two readers

You get risk in francs and legal duties. Your IT gets traces and fixes. Same signed document.

THE RECEIPTS10+ REDACTED CASES100+ VERIFIED FINDINGS0 FALSE POSITIVESSEE THE TRACK RECORD →
STEP 03 — THE SHIELD

One subscription. Built from your modules.

Your Shield keeps permanent watch on the same modules as your First Engagement — those, no more, no less. Add, drop or swap modules mid-subscription as the business evolves (a new module starts with its own first engagement), and retune the cadence anytime. A full re-assessment is included every 4 months; step it up to monthly or weekly. The continuous check runs daily by default — tune it down to weekly sweeps or up to second-by-second.

For scale: external IT support for an 8-person Swiss firm runs CHF 50–80k a year. The Shield is built to sit well under what you already pay to keep the lights on.

In every ShieldINCLUDED, ANY MODULE MIX
Attack-surface & CVE monitoring
Continuous check — daily included
Credential-leak watch
Big re-assessment every 4 months
Retest of every fix you ship
Direct line to the researcher
ANNUAL FEE = YOUR MODULES × CADENCE — FIXED IN WRITING · DRAFT IT IN THE CALCULATOR BELOW

Could someone get in…

CLICK TO TOGGLE · WHITE- OR BLACK-BOX, PER MODULE
WHITE BOXWe test with knowledge — accounts, architecture, source. Every franc goes into depth.
BLACK BOXWe start blind, like a real outsider. Maximum realism — discovery burns budget, so it costs more.
+ THE DIFFERENCE
APPLICATION
…through your website or app?

Standing deep-dive on the product your customers touch — beyond the first pass.

MODE
CLOUD
…through your cloud setup?

Inside your AWS, Azure or GCP: permissions drift, exposed keys, forgotten services — continuously.

MODE
SOCIAL ENGINEERING
…by fooling one of your people?

Phishing and pretexting, run safely — also available standalone with awareness training.

MODE — BLACK-BOX BY NATURE · THAT'S THE POINT OF PHISHING
NETWORK
…through your network or Wi-Fi?

Segmentation, VPN, wireless — the paths between your systems.

ASSUMED BREACH
…from one infected laptop?

We start inside — and measure how far a single compromised device gets.

SUPPLY CHAIN
…through one of your suppliers?

Vendors, dependencies and integrations as a way into you.

AI / LLM
…through your AI features?

Prompt injection, data leakage, runaway agents — tested before someone else does.

VIBE-CODING
…through code AI wrote for you?

AI-generated auth, validation and dependencies — checked for inherited flaws.

SOFTWARE
…through the software you ship?

Your own product, reviewed the way an attacker reads it — code to runtime.

…and beyond red, on request.

FLAG IT HERE — IT RIDES ALONG IN YOUR DRAFT

We work alongside your existing IT — internal or external. They keep things running; we prove it's safe. No overlap, no turf war, no pressure to switch providers. When you want more than proof, flag the blue side — through us and vetted partners, scoped separately from the calculator.

PURPLE TEAM+ ADD TO THE CALL
Attack and defense, one table.

We run the offense live while your IT tunes detection and response in real time — findings become muscle memory, not a PDF.

ON REQUEST — SCOPED SEPARATELY
AWARENESS TRAINING+ ADD TO THE CALL
Your people, trained on real lures.

Standalone or after a social-engineering round: sessions built on the exact e-mails and calls that would have fooled your team.

ON REQUEST — SCOPED SEPARATELY
SOC-LITE / ALERTING 24/7+ ADD TO THE CALL
Someone watching, around the clock.

Shield monitoring wired into a 24/7 alert pipeline — run with vetted partners, or plugged into the provider you already have.

ON REQUEST — SCOPED SEPARATELY
MANAGED IT & HARDWARE+ ADD TO THE CALL
IT and hardware, security-first.

Day-to-day IT run — or hardware bought right — through vetted partners, coordinated with the security picture. Only if you ask.

ON REQUEST — SCOPED SEPARATELY

Your Shield, in numbers.

EVERYTHING YOU TOGGLED, PRICED LIVE — INDICATIVE BY DESIGN
YOUR SHIELD — 3/9 MODULESAPPLICATION · CLOUD · SOCIAL ENG.COMPANY SIZE
BIG RE-ASSESSMENTCONTINUOUS CHECK
MODULES AND CADENCE STAY FLEXIBLE DURING THE SUBSCRIPTION — A NEW MODULE STARTS WITH ITS OWN FIRST ENGAGEMENT, THEN JOINS THE WATCH
FIRST ENGAGEMENT — ONE-OFF
CHF 20'500CHF 17'800LAUNCH OFFER
3 MODULES · ≤ 1 WEEK, EVERYTHING ACTIVE, EACH AT 100%
THE SHIELD — PER YEAR
CHF 17'500/yrCHF 15'200/yrLAUNCH OFFER
3 MODULES · RE-ASSESS / 4 MO · CHECK DAILY · CHANGE ANYTIME
LAUNCH OFFER FOR OUR FIRST CLIENTS — ALREADY APPLIED TO THE TOTALS ABOVE · LAST 8 SLOTS · VALID UNTIL 13 SEP 2026
LOCKED IN WRITING AT THE DISCOVERY CALL · ONBOARDING IS SEQUENTIAL — FIRST ENGAGEMENTS SCHEDULED IN ORDER OF SIGNATURE
SHARED CORE APPLIED — RECON, PLATFORM & REPORTING RUN ONCE: EVERY MODULE AFTER THE FIRST −25%
INDICATIVE, DRAFT PRICING — IT GIVES DIRECTION, TO YOU AND TO US. THE FINAL QUOTE IS FIXED, IN WRITING, AFTER THE DISCOVERY CALL
STRAIGHT ANSWERS

The questions executives actually ask.

QWhat if you find nothing?

Then you get signed evidence of exactly that — what we tested, how deep, and what held. Your auditor, your insurer and your board can verify it. Either way, the Shield keeps checking as things change.

QWill the testing break something?

No. Every engagement runs under a written scope ruling and our reconnaissance policy — engineered to prove impact without causing it. Anything intrusive is agreed first, in writing.

QWe already have an IT provider.

Keep them — we're not a replacement. They run your systems; we independently verify them. Findings arrive as fix-ready traces your provider can act on, and we retest their fixes at no extra cost.

QAren't we too small to be a target?

Attacks are automated — they don't check your headcount. Small firms get hit precisely because attackers assume nobody is watching. The Shield makes that assumption wrong.

QCan we stop the subscription?

Yes — quarterly, no lock-in. Everything we produced stays yours: reports, evidence, fixes. If you come back later, your history comes back with you.

There's no exit fee and no clawback on anything you've already fixed. We close out with a final signed report and a clean export of every finding — plus a short handover note your own IT or next provider can pick up cold.

QHow is the fee set?

By the modules you activate — each priced for your size, white- or black-box, sharing one platform core (every module after the first: −25%) — and the cadence you choose; daily check and 4-month re-assessment come with every subscription. Add, drop or swap modules mid-subscription; a new module starts with its own first engagement. All nine together earn −10%. Always fixed before we start, in writing. Never per finding, never an "urgent" upsell.

QWhite box or black box — which penetration test do we need?

White box tests with knowledge — accounts, architecture, source — so the whole budget goes into depth. Black box starts blind, like a real outsider: maximum realism, more budget burned on discovery, priced +20–45% by module. Most companies mix — black-box what the internet sees, white-box what's behind the login. The calculator above prices both.

QRed team, blue team — what's the difference?

Red attacks, blue defends. The Shield is red: we prove how you'd be breached before someone else does. Blue is detection, response, training and operations — available as extra modules above, with vetted partners. Purple is both at one table: we attack live while your IT tunes the defenses.

QHow much does a penetration test cost in Switzerland?

Swiss market, 2026: CHF 8–15k for a web-application test, CHF 10–25k for infrastructure, CHF 8–18k for mobile or APIs; a full multi-week crew assessment at CHF 700/hour lands at CHF 84–126k. QSearch modules start at the low end of those ranges, and every module after the first costs −25% — recon and reporting run once. Fixed in writing, and the engagement doesn't end: the Shield keeps watching and re-testing all year.

QHow often should a company test its security?

Attackers don't wait for your annual audit. After one complete engagement, continuous coverage — daily checks plus a big re-assessment every 4 months — keeps pace with every deploy, hire and new CVE. That's exactly what the Shield is.

MORE QUESTIONS? A RESEARCHER ANSWERS THEM ON THE CALL — NOT A SALES TEAM

Every shield is tailored. Every fee is fixed.

One conversation — scoped to your business, not a product catalog. If we're not the right fit, we'll tell you.