Field notes

Notes from building Cairn

Occasional writing on the craft of pentest delivery: the formats, the workflows, and the decisions behind the platform. Written by the people who build it, for the people who run engagements.

What we write about

Most writing about penetration testing covers how to find the bug. Almost none of it covers what happens afterwards: the scoping call that set the boundaries, the Statement of Work that priced it, the finding library that had to be rewritten because it lived in a format nothing else could read, and the client who wanted the report as something other than an emailed PDF. That gap is what these notes are about.

Recurring themes: portable data, because a finding library outlasts any tool that stores it, which is why we published the Open Pentest Format as an open specification anyone can implement rather than a Cairn feature. The whole engagement, because the pre-sales half decides margin and nobody tools it. And keeping data where it belongs, because an offensive team’s findings are among the most sensitive documents in its clients’ estate, which is what drives the on-prem and air-gapped work described under capabilities and security.

If you want to see what the platform actually does rather than read about the thinking behind it, the screenshots are real captures from a live tenant, and pricing is published in full.