A professional hacker, retained rather than hired
Sentinel Black is a small practice. Every mandate is led personally by a senior professional hacker, so the person you meet is the person on your systems from first day to last. We accept a limited number of engagements each year.
Most firms sell you a brand, but they staff the work with whoever is free that month.
We sell the opposite. A named principal, a fixed fee, and a written boundary neither of us crosses.
What a professional hacker is retained to do
An engagement is a judgement about people before it is a purchase. Therefore these five commitments sit here rather than in the small print, because they are what you are actually buying.
Why a professional hacker is judged on discretion
Our institutional practice comes first. We work with security teams inside large organisations, on retainer and on named engagements, and that is the bulk of the year.
Alongside it we take a small number of private mandates. Those are reserved for founders, executives, and families facing a technically complex threat, and a senior principal leads them directly. We do not advertise that side of the practice, so it arrives by introduction.
In either case the engagement letter is signed before any technical discussion begins. Consequently nothing sensitive is ever discussed on an unprotected first call.
Terms, before anything technical
Every mandate runs on the same terms. They are short on purpose, since a clause nobody reads protects nobody.
- Authorisation
- Written permission from the system owner, obtained before any technical work.
- Scope
- A defined list of systems, with everything outside it explicitly out of bounds.
- Confidentiality
- Mutual non-disclosure signed first, and no client named without written consent.
- Fee
- One fixed number, agreed after scoping, invoiced against milestones.
- Insurance
- Professional indemnity and cyber liability cover, evidenced on request.
- Retention
- Nothing kept. Evidence and findings destroyed when the engagement closes.
Engagements we decline
We say this plainly because the request arrives often, and a polite silence helps nobody.
- Access to any account, device or system without the owner's documented consent.
- Surveillance of a private individual, whatever the relationship to the requester.
- Recovery of an account that belongs to somebody else.
- Alteration of records, balances or logs held by another party.
- Identifying or retaliating against whoever attacked you. That belongs with law enforcement.
Unauthorised access is a criminal offence in both jurisdictions where we operate, and in the United Kingdom it is an offence regardless of intent. If a request touches the list above, we are not the right firm, and it receives no reply.
One finding, redacted
We publish no case studies with names on them. However, the shape of the work can be shown, so here is a single critical finding from an authorised engagement.
- Client
- Retail group, North America
- Entry
- A build runner token left readable in a public job log
- Chain
- Token to over-scoped role to vault path to backup operator to domain controller
- Elapsed
- 41 hours from the opening of the testing window
- Impact
- Full control of the production identity plane
- Remedy
- Three configuration changes, no downtime, confirmed on the included retest
Most mandates settle between $35,000 and $120,000, and red team work begins higher.
The fee is fixed after a scoping conversation, so there is no hourly billing and no revision mid-engagement. We do not discount. Where a budget will not carry the scope, we adjust the scope instead, and if that is not possible we say so.
Questions about retaining a professional hacker
What does a professional hacker actually do?
In short, the work is authorised attack simulation. We attempt to reach something valuable using the same methods a real intruder would, then hand back the route, the evidence, and the remedy. Written permission from the system owner is what separates the profession from the offence.
Why will you not show client logos?
Because our clients hire us on the understanding that the engagement stays private. A logo wall would break that on day one. Instead we arrange a reference call with a comparable client once mutual non-disclosure is in place.
Do you work with private individuals?
We accept a small number each year, usually founders, executives, or families facing a genuine and technically complex threat. A senior principal leads that work directly, and the terms are identical to our institutional mandates.
How do you handle confidentiality?
Mutual non-disclosure is signed before any technical discussion. Evidence moves over encrypted channels while the work is live, and everything is destroyed when the mandate closes. Moreover, no engagement is subcontracted, so the circle stays small.
What does a mandate cost?
Mandates start at $25,000 and most settle between $35,000 and $120,000. The number is fixed after the scoping conversation. We do not discount, although we will adjust scope where a budget cannot carry the depth.
How quickly can you begin?
That depends on capacity, since we run a limited number of engagements at once. Where a window is free, work usually begins within two weeks of the signed engagement letter.