// How it works
Three steps for you. Careful rules behind each one.
- 1
Preflight
Answer a short questionnaire: what we're reviewing — an internal app, a public website or infrastructure — who uses it, what data it touches, where it runs. No scanning, no probing.
- 2
Confirm authority
A business owner names the legal entity and an authorized technical contact. Paying never authorizes testing on its own.
- 3
Prepare synthetic staging
Together we name up to two roles, ten critical workflows, expected access outcomes, exclusions, test accounts and stop conditions.
- 4
Checks run
Specialized modules replay each request with every role, test your in-app assistant's tools, and read site and infrastructure configuration passively. Nothing counts as a finding without a recorded request and response. On the locked scope, Live test shows each check while it runs: what it is looking for, then the stored status. Real requests only, sanitized. A line is not a finding.
- 5
Analyst review
A qualified analyst reviews evidence, coverage and the proposed readiness decision before anything reaches you.
- 6
Understand the result
A one-page decision summary, a coverage matrix, findings with Liquid guidance, repair prompts and local verification prompts. There is no site-secure seal. A private quote is allowed only when every material layer was recorded and no Critical, High, or Medium finding is still open.
- 7
Independent retest
After your change, we repeat the named checks under refreshed authorization and record fixed, still present or inconclusive.
Never in the standard profile
- Real employee, customer, payroll or financial records
- Purchases, outbound messages or permission changes
- Destructive operations or password attacks
- Testing discoveries you didn't authorize

> liquid.explaining
If something can't be tested safely, I'll mark it blocked or not tested in the report instead of guessing. Gaps are part of the answer.