Dunicot A cybersecurity consultancy and advisory firm.

Compliance · Audit evidence

Evidence your auditor will accept.

Dunicot operates a certified ISO/IEC 27001 information security management system, certified in the name of Dunicot Private Limited and governing engagements contracted through either entity, Dunicot Private Limited in Pakistan or Dunicot LLC in the United States. The certificate and its scope statement are provided to clients and prospects on request under NDA, together with the current statement of applicability.

Every engagement includes

01

Executive summary

One page for the people who approve budget: what was tested, what was found, what it means in business terms.

02

Technical findings

Each finding with severity, CVSS, affected component, full request and response, reproduction steps and a working proof of concept.

03

Attack chains

Where findings combine, the chain is written out end to end, from first request to demonstrated impact.

04

Remediation guidance

A specific fix for your stack and framework, with the corrected pattern, not a link to a generic reference page.

05

Audit mapping

Findings mapped to SOC 2, ISO 27001, PCI DSS, HIPAA and OWASP ASVS as applicable, so the report drops straight into an audit pack.

06

Retest and attestation

Every finding retested in a clean session after remediation, with a signed attestation letter for customers and auditors.

Audit date already set?

Engagements are scheduled backwards from your deadline, so findings are remediated and re-verified before the auditor arrives.