Sorami / About

Senior engineers.
We do the work ourselves.

No account manager sits between you and the person testing your systems. The people who scope your engagement are the people who deliver it.

What Sorami is

A narrow practice, on purpose.

  • Sorami Consulting Pty Ltd, ACN 702 116 452, registered in Australia.
  • Senior engineers who deliver, rather than resell.
  • Cloud architecture, security testing and compliance readiness.
  • Work happens in your repositories and your cloud accounts.
  • You keep the findings register, the decision records and the evidence index.

The service list is deliberately short. Engineers who go deep on cloud and security cannot also cover every service line, and a firm that claims to is describing a sales team rather than an engineering one. Our security practice and cloud practice are what we do.

Our names

Named on engagement, not on the website.

We publish no personal names here. That is a policy rather than an oversight, and there is a reason for it.

  • A published engineer name is a target for social engineering.
  • It is also a recruiting list for anyone who wants our people.
  • Security testers are named by policy in the proposal, not in public.

What you get instead, and before you sign anything:

  • The named people on your engagement, written into the proposal.
  • An introduction call with the person who will do the work.
  • CVs and certification evidence on request, under NDA.
Certifications

What our testers hold.

Acronyms are expanded in full, because these usually end up pasted into somebody’s audit checklist.

Offensive

Certifications behind the penetration testing work.

  • OSCP, OffSec Certified Professional.
  • OSWE, OffSec Web Expert.
  • OSCE, OffSec Certified Expert.
  • OSWP, OffSec Wireless Professional.
  • CRT, CREST Registered Penetration Tester.
  • eCPPT v2, Certified Professional Penetration Tester, eLearnSecurity and INE Security.
  • RTO v1, Certified Red Team Operator, Zero-Point Security.

Cloud

Certifications behind the cloud architecture and review work.

  • AWS Security Specialty, AWS Certified Security, Specialty.
  • AWS SAA, AWS Certified Solutions Architect, Associate.

Defensive

Certifications behind detection and response work.

  • CCFA, CrowdStrike Certified Falcon Administrator.
  • CCFH, CrowdStrike Certified Falcon Hunter.
  • CCFR, CrowdStrike Certified Falcon Responder.
What we do not do

The list matters more than the capability list.

  • No managed security service and no round-the-clock monitoring.
  • No reselling, no partner tier and no margin on your licences.
  • No certification, audit or attestation. We prepare you for the body that issues it.
  • No legal advice. We are engineers, and your lawyer covers the legal position.
  • No staff augmentation by the month with no defined outcome.

Where the work is outside that boundary we say so on the first call, and we will point you at a firm that does it.

How we handle proof

Judge the work before you buy it.

Our output, our method and our boundaries are published. You can read all three today without booking a sales call. Here is what is on the site:

  • The deliverable formats, so you can judge the output before buying.
  • A full 19-page illustrative report, free and ungated.
  • The exclusions we write into every scope, in public.
  • The failure modes we expect, on each service page.
  • Primary sources by document and version, linked so you can check them.

Start with what a penetration test report should contain, which is the standard we hold our own reporting to, and our trust centre for how we handle your data.

Questions before you book

Practical answers.

Who will actually do the work?

The senior engineers who scope your engagement stay on it to delivery. Testing is carried out by certified testers whose qualifications are listed on this page. You are not handed to a graduate after the sales call.

Why are there no names on the site?

A published name is a target and a recruiting list. We name the people on your engagement in the proposal, and we will introduce them on a call before you sign. Ask and you get CVs under NDA.

Can you show us case studies?

Yes, in the form that is actually useful. Read the published 19-page illustrative report, which is the exact deliverable format you would receive. It shows the scoping method and the exclusions we write into every scope. Client work stays confidential under the engagement terms.

Will you clear our procurement requirements?

Send us the requirements with your scoping request and we will answer them in writing. Where a requirement calls for a company accreditation rather than certified engineers, we tell you in week one rather than week six.

What is the legal entity?

Sorami Consulting Pty Ltd, ACN 702 116 452, registered in Australia. That is the entity on every proposal and every invoice.

Let’s scope it

Want to meet the people first?

Ask for an introduction call before any proposal. We will bring the person who would run your engagement.

Send an enquiry

Last reviewed: