# Depth Security > Official Depth Security business agent. Depth Security is an offensive security firm offering network, application, and Active Directory penetration testing… ## Ask it a question Depth Security answers for itself at https://api.hailera.com/mcp/depthsecurity. A client that speaks MCP can connect to that address; the tool is ask_depthsecurity and the protocol is 2026-07-28. Where this file and the agent disagree, the agent is current. ## About Depth Security Depth Security is an offensive security company that performs penetration testing. Its published services are Network Penetration Testing, Application Penetration Testing, Adversary Emulation, Active Directory Password Security Analysis, and Active Directory Security Essentials Review. The site's tagline reads "If there's a way in, we'll find it. Then we'll show you how to fix it." The company describes itself as "a division of Konica Minolta Business Solutions U.S.A., Inc." The Who We Are page says Depth Security was "established by a tight-knit group of seasoned engineers who continue to lead the company today," that its team "brings decades of hands-on experience in IT security," and that "we never outsource our work; every member of our team is a dedicated full-time employee." The page states "thousands of assessments performed." Six reasons to choose the firm are listed: accuracy (issues are manually validated, described as "no false positives in our reports"), communication (a dedicated assessor and weekly updates on assessment progress), experience, protection, quality, and understanding (nothing is labeled "Critical" unless it has been exploited). An Industries page covers healthcare, manufacturing, finance, and legal organizations. Jake Reynolds is named on the home page as Director of Offensive Services. The website does not publish a founding year, staff certifications, headcount, or a street address, and it does not publish prices, rates, fees, or business hours. To contact the company about services, phone (816) 299-4123 or email info@depthsecurity.com. Source: https://www.depthsecurity.com/who-we-are/ ## Where Depth Security works Lists Mobile as a location. Areas beyond these are not published. ## How Depth Security works with clients The Contact Us page lists two routes. For sales information the page publishes sales@depthsecurity.com and the phone number (816) 299-4123. For general information it publishes info@depthsecurity.com. The site footer repeats info@depthsecurity.com and the same phone number on every page. The contact page also carries a web contact form. Depth Security does not publish any price, prices, pricing, cost, rate, or fee for any service, and it publishes no sample quote or estimate; a customer who wants a quote or an estimate has to contact the company directly by phone, email, or the form. The way the site invites people to start is a free consultation: service pages say "Schedule a free consultation to connect with an offensive cybersecurity expert" and "Book Your Free Consultation." There is no online booking or appointment calendar on the site, and no stated lead time for scheduling an engagement. The website does not publish a street address, a mailing address, an office location, business hours, or the days or hours it is open, and it does not list areas served or a service-area map, so where the company is located and where it works are not stated on the site. The company is described as a division of Konica Minolta Business Solutions U.S.A., Inc. The Industries page names healthcare, manufacturing, finance, and legal as markets it addresses. Depth Security also publishes a GitHub account and a blog under Resources. Source: https://www.depthsecurity.com/contact-us/ ## Active Directory password and security review services Depth Security offers two Active Directory services. The Active Directory Password Security Analysis page says the service gives organizations "the ability to identify all crackable passwords and implement positive changes to prevent future breaches," and notes that while organizations may rely on MFA after a credential compromise, "our experience reveals widespread weaknesses and gaps in MFA deployment." Four elements are listed: dedicated password-cracking hardware developed in-house "incorporating dictionaries, cracking rules, and conditions"; a Password Review producing detailed reports on user password habits plus separate reports for executives, managers, and engineers; identification of users with easily guessable passwords and "repeat IT offenders" who reuse the same password or format; and a flexible methodology using custom seed words and adaptable deliverables. Separately, the Active Directory Security Essentials Review, described on its own page at /pen-testing/active-directory-security-essentials-review/, provides "a thorough checklist of potential security risks," covering Active Directory vulnerabilities, privilege escalation, and lateral movement. Its listed parts are a Configuration Review (including AD Certificate Services configuration issues), identification of weaknesses such as service account vulnerabilities, and a Privileges Review that assesses account configurations and flags abnormal privileges and weaknesses in DNS and DHCP setups. Neither page publishes a price, cost, estimate, rate, fee, or turnaround time. To ask about either service, phone (816) 299-4123 or email sales@depthsecurity.com. Source: https://www.depthsecurity.com/pen-testing/active-directory-password-review/ ## Adversary emulation and red team services Adversary emulation, which Depth Security also calls Red Team testing, is described as an assessment "for organizations with mature information security programs that want to improve their organization's security posture." The page says the approach "replicates the tactics, tools, and techniques used by highly skilled attackers" and "encompasses evasion, social engineering, and physical attacks, simulation of the latest malware, and sophisticated attack campaigns." It is described as a goal-oriented exercise run by "a team of expert testers employing a 'no holds barred' strategy," suited to companies that found traditional penetration testing insufficient. The site states this testing "is more expensive than standard penetration testing" and is "focused on achieving specific objectives rather than identifying every flaw"; no actual price, cost, rate or fee figure is published anywhere on the site. Four services are listed. Red Team assessments evaluate defense, detection, and response capabilities across technical, social, and physical domains, with "extended timelines and multiple concurrent assessors." The Purple Team Workshop helps defenders distinguish genuine threats from noise and monitor for suspicious behavior. Phishing / Spear Phishing simulations are customizable, with a personalized scenario built for the client's environment, measuring responses such as clicks, page views, and credential submissions. Physical Security services evaluate physical access controls and employee compliance with security policies. The page invites visitors to reach out to the adversary emulation experts; contact details are (816) 299-4123 and sales@depthsecurity.com. Source: https://www.depthsecurity.com/pen-testing/adversary-emulation/ ## Application penetration testing services Depth Security's application security assessment services are described as designed "to identify these vulnerabilities before they can be exploited" in web and mobile applications. The stated methodology "mirrors attackers' techniques, combining both automated and manual approaches," and key features listed are "manual penetration testing with zero false positives, both unauthenticated and authenticated testing, and detailed exploitation and escalation reports." Applications are tested from multiple user levels "to ensure, for example, that Customer A cannot access Customer B's data," which the page says matters for clients who develop and sell their own applications and for cloud environments. Six application services are listed. Web Application testing evaluates applications from public (not logged-in) and authenticated (logged-in) viewpoints, examines inter-role authorization where an app has multiple permission roles, and for multi-tenant apps focuses on cross-tenant access. API / Web Services testing covers B2B web services that communicate over HTTP and interact with databases. Hybrid Application (Run time and Code Review) combines run-time and static analysis. Continuous application security assessment provides ongoing detection and is described as suited to organizations with fast-paced development. Thick Client testing covers those applications and the services they interact with. Mobile Application assessment is designed to reveal server-side and device-side risks. The page invites visitors to book a free consultation with an application penetration testing specialist. No price, cost, quote figure, rate, or fee is published on the site; contact sales@depthsecurity.com or (816) 299-4123 for information. Source: https://www.depthsecurity.com/pen-testing/application-penetration-testing/ ## Network penetration testing services Depth Security's network penetration testing is described as a way "to understand the real-world risks facing your infrastructure, applications, and users," using "the same tools and techniques as attackers" to uncover actual rather than hypothetical vulnerabilities. The page says reports include "practical, prioritized recommendations for remediation, presented in formats that are easily digestible for executives, managers, and technical staff alike," and that "everything we do is vetted manually." Six network services are listed. External Discovery (also called Perimeter Discovery) provides a view of external systems and data "going beyond basic DNS and IP enumeration." External Network testing is performed as an internet-based attacker against internet-exposed assets. Internal Network testing is conducted inside the organization's network and mimics an intrusion by an insider with authorized access, such as a staff member or contractor. Wireless testing is performed from the perspective of an attacker within wireless range and assesses encryption protocols, network segmentation, access controls, and monitoring. Trusted Access testing mimics a partner or vendor connected through remote access technologies, listed as including VPN, SSLVPN, and Citrix. Continuous testing starts with an annual test and then continues throughout the year; the page notes penetration testing is typically done annually, semi-annually, or quarterly. The page offers a free consultation with a network penetration testing expert. It does not publish any price, cost, rate, fee, or engagement schedule. To book a consultation, contact (816) 299-4123 or sales@depthsecurity.com. Source: https://www.depthsecurity.com/pen-testing/network-penetration-testing/ ## What Depth Security has not published yet These are things people ask Depth Security that its published information does not yet cover. - prices - availability - engagement timelines or lead times - compliance or certification outcomes - guarantees that all vulnerabilities are found - contract or scope terms - office location, address or hours - staff certifications or credentials Ask anyway — the agent will say plainly that it is not published rather than guess. ## Where this comes from https://www.depthsecurity.com