If you've bought security services before, you probably know the routine: an unsolicited call, a sales deck, a quote, then a deposit before anyone starts testing anything. We work differently. We never ask for money up front, we don't do telemarketing, and every one of our clients came to us through a referral. Here's what that looks like in practice, and why we've chosen to work this way.

We never ask for money up front

There's no deposit, no prepayment and no retainer paid in advance. You pay only once the work is complete and you have your final deliverable in hand.

We do it this way because it puts the risk where it belongs. When a client pays before the work begins, the firm has already been paid whether the result is good or not. When payment comes at the end, the work has to stand on its own. You see exactly what you're paying for before you pay for it.

The same principle applies to ongoing services such as virtual CISO support and vulnerability management: you're billed for work after it has been performed, never in advance.

We don't do telemarketing, and we don't call prospects

We're a cybersecurity firm, not a sales or marketing company. Nobody from Radical Security will call you out of the blue to sell you a penetration test. We don't do telemarketing and we don't call prospects. If you hear from us, it's because you asked us to get in touch or because we're already working together.

That has a useful side effect. If you get an unsolicited sales call from someone claiming to be from Radical Security, it isn't us. Don't share system details, credentials or payment information, and don't pay an invoice or deposit request you weren't expecting. Email [email protected] and we'll confirm whether the contact was genuine.

Our clients come through referrals

All of our clients came to us through referrals from our network. Many of them are long-term relationships: security and IT leaders we first worked with at a previous company, who brought us in again when they moved to a new organization.

We think that's the best measure of a security partner. A client who hires you once might have been persuaded by a good pitch. A client who hires you again from a different company, years later, is telling you the work held up. It also means we start every engagement with context. Long-term clients don't have to re-explain how they think about risk, because we already know.

A business that grows only through referrals has a simple rule: it can't afford unhappy clients. That's the thinking behind our 100% money-back guarantee.

What an engagement looks like

From first contact to final invoice, a typical engagement runs like this:

  1. You reach out. Usually after an introduction from someone in our network. We don't make the first call.
  2. We scope the work together. We learn about your environment, your goals and any compliance drivers such as PCI DSS, SOC 2 or HIPAA, and recommend the right service.
  3. We agree on scope in writing. Scope, timeline, deliverables and price are set before any work begins. No deposit is required.
  4. We do the work. If we find something critical along the way, we tell you right away.
  5. We deliver the results. You receive the final report or deliverable, with clear findings and remediation steps.
  6. Then you pay. We invoice once the work is complete.

The full process is laid out on our How We Work page.

Backed by a money-back guarantee

Paying at the end already lowers your risk. Our guarantee removes what's left. If you're not satisfied with an engagement, tell us within 30 days of your final deliverable and choose: we fix it at no cost, or you get a full refund. If you haven't paid the invoice yet, we hold it while we make things right, and if you choose a refund, you simply don't pay. I explain the thinking behind it in Why We Back Every Engagement With a 100% Money-Back Guarantee.

How to get in touch

Because we don't call anyone, the first move is always yours. Whether a colleague referred you or you found us on your own, email [email protected] and tell us what you need tested, assessed or fixed. You won't be added to a call list, and nothing is due until the work is done.

Key takeaways

  • We never ask for money up front. You pay only once the work is complete.
  • We don't do telemarketing and we never call prospects. An unsolicited sales call in our name isn't from us.
  • All of our clients come through referrals, and many have worked with us across several companies.
  • Every engagement is backed by a 100% money-back guarantee.