Proof, Not Promises

Real engagements, real outcomes. Client details are anonymized to protect confidentiality. The results are not.

Security buyers don't make decisions on service descriptions. They make them on evidence. Below are examples of what working with Caliber looks like and what it delivers: the situation a client faced, what we did, and what changed as a result.

Case Study 01
Penetration Testing
The Client
  • Industry: Enterprise software, global operations
  • Location: International
  • Company size: 100,000+ employees
  • Service: Application, desktop, API, and network penetration testing
  • Engagement model: Ongoing, recurring testing partner
The Situation

A global enterprise software organization needed penetration testing across a complex environment: applications, desktop software, APIs, and network infrastructure. At their scale, security testing isn't a once-a-year checkbox. It's continuous, and it has to keep pace with how fast their teams ship and change. They needed a partner who could go deeper than a surface scan, move on their timeline rather than a rigid vendor schedule, and report in a way their teams could actually act on. They are large enough to work with anyone, and they vet their vendors accordingly.

What We Did

Caliber became one of a small number of trusted security testing partners for the organization, performing manual, expert-led penetration testing across their application, desktop, API, and network surfaces. Rather than a fixed, one-size engagement, we structured the work to flex with their needs, scaling and shifting focus as their priorities and release cycles demanded.

What We Found / Delivered

Where most firms simply collect scope and run a fixed test, Caliber works collaboratively with the client's teams to shape the testing landscape, directing each engagement based on real discussion of where risk actually lives. That collaboration consistently produces deeper, more relevant findings than a standard scoped test would surface, because the testing is aimed at what matters most to the client, not just a generic checklist.

The Result

The organization keeps Caliber as one of just three security testing firms it relies on, alongside far larger competitors. The clearest signal of that trust: when Caliber raised its rates, the client kept the engagement without hesitation, because the depth of testing, the agility to move as their needs changed, and the quality of reporting were worth it. Caliber remains a fraction of the cost of the larger firms on their roster while delivering work they consider essential.

Case Study 02
Application Security
The Client
  • Industry: Banking and financial services
  • Location: Washington
  • Company size: ~3,000 employees
  • Service: Ongoing application security testing and secure code review
  • Engagement model: Monthly recurring service
The Situation

A regional financial institution offered a mobile banking app that let customers access their accounts and transaction history. The app was updated roughly once a month, and every update carried risk: new code means new opportunities for vulnerabilities to slip in. The client had no in-house specialist who could perform the penetration testing and security review their release schedule demanded, and the gap left them shipping updates without knowing what those updates might expose.

What We Did

Caliber stepped in to run monthly penetration testing and vulnerability scanning on the client's mobile application, timed to their release cycle. Unlike a one-and-done pen test, this was built as an ongoing program. We created a standardized, repeatable review process tailored to their product, so every update was measured the same way, month over month.

What We Found / Delivered

Each month, Caliber delivered a report that identified and prioritized the vulnerabilities found in that release, along with a consistent metric the client could track against prior months. That gave them a clear before-ship view of what was broken and what to fix first, plus a running measure of whether their secure coding practices were actually holding up over time.

The Result

The client now catches and remediates security issues before each update ships, instead of discovering them after customers are already exposed. Just as important, they get this without having to hire and maintain a dedicated security specialist, freeing their team to focus on the product itself. Caliber operates with the responsiveness of an embedded internal team rather than a distant vendor, and the client points to that close, ongoing communication as a core part of the value of the partnership.

Case Study 03
Staff Augmentation
The Client
  • Industry: Technology
  • Location: Bay Area, California
  • Company size: ~7,000 employees
  • Service: Security staff augmentation, application security specialists and security project support
  • Engagement model: Project-based, typically six-plus months
The Situation

The client repeatedly hit periods where it needed to increase security capacity quickly, but only for a defined stretch. A surge of application security work, a critical project on a deadline, or a key team member heading out on parental leave or military deployment left a real gap, and a hard choice: make a permanent hire it wouldn't need long term, or let productivity slip. What the client needed was deeply technical security talent that could step in quickly and contribute from day one, without the cost and commitment of a full-time addition.

What We Did

When the client hit a surge of application security work, Caliber placed a vetted, senior application security specialist with them inside of two weeks. The specialist ramped in immediately and contributed from the first week, with no lengthy onboarding. The engagement was scoped at six months to cover the crunch. On other occasions, when team members went out on parental leave or military deployment, Caliber filled those gaps the same way, including with generalist security and security project management coverage when that was what the client needed.

What We Found / Delivered

The placements held. Engagements scoped for six months repeatedly extended well past their original terms, several running a year or longer, because the people Caliber placed became genuinely useful to the teams they joined. The client returned to Caliber for each new gap and surge rather than starting a vendor search over each time.

The Result

The client got the added security capacity it needed during each crunch and absence without making a permanent hire it would have had to carry afterward. Critical application security work stayed on schedule, gaps from leave and deployment were covered without disruption, and the client built an ongoing, repeatable way to scale its security team up and down as demand required.

Your situation is the next case study.