Sorami / About

Senior engineers.
We do the work ourselves.

No account manager sits between you and the person testing your systems. The people who scope your engagement are the people who deliver it.

What Sorami is

A narrow practice, on purpose.

  • Sorami Consulting Pty Ltd, ACN 702 116 452, registered in Australia.
  • Senior engineers who deliver, rather than resell.
  • Cloud architecture, security testing and compliance readiness.
  • Work happens in your repositories and your cloud accounts.
  • You keep the findings register, the decision records and the evidence index.

The service list is deliberately short. Engineers who go deep on cloud and security cannot also cover every service line, and a firm that claims to is describing a sales team rather than an engineering one. Our security practice and cloud practice are what we do.

Our names

Named on engagement, not on the website.

We publish no personal names here. That is a policy rather than an oversight, and there is a reason for it.

  • A published engineer name is a target for social engineering.
  • It is also a recruiting list for anyone who wants our people.
  • Security testers are named by policy in the proposal, not in public.

What you get instead, and before you sign anything:

  • The named people on your engagement, written into the proposal.
  • An introduction call with the person who will do the work.
  • CVs and certification evidence on request, under NDA.
Certifications

What our testers hold.

Acronyms are expanded in full, because these usually end up pasted into somebody’s audit checklist.

Offensive

Certifications behind the penetration testing work.

  • OSCP, OffSec Certified Professional.
  • OSWE, OffSec Web Expert.
  • OSCE, OffSec Certified Expert.
  • OSWP, OffSec Wireless Professional.
  • CRT, CREST Registered Penetration Tester.
  • eCPPT v2, Certified Professional Penetration Tester, eLearnSecurity and INE Security.
  • RTO v1, Certified Red Team Operator, Zero-Point Security.

Cloud

Certifications behind the cloud architecture and review work.

  • AWS Security Specialty, AWS Certified Security, Specialty.
  • AWS SAA, AWS Certified Solutions Architect, Associate.

Defensive

Certifications behind detection and response work.

  • CCFA, CrowdStrike Certified Falcon Administrator.
  • CCFH, CrowdStrike Certified Falcon Hunter.
  • CCFR, CrowdStrike Certified Falcon Responder.
What we do not do

The list matters more than the capability list.

  • No managed security service and no round-the-clock monitoring.
  • No reselling, no partner tier and no margin on your licences.
  • No certification, audit or attestation. We prepare you for the body that issues it.
  • No legal advice. We are engineers, and your lawyer covers the legal position.
  • No staff augmentation by the month with no defined outcome.

Where the work is outside that boundary we say so on the first call, and we will point you at a firm that does it.

How we handle proof

A new company with no clients to name.

Sorami is new. There is no client list, and the honest response is to say that rather than to manufacture one.

What we will never publish:

  • Case studies for work that did not happen.
  • Client logos, and none at all without written permission.
  • Testimonials, ratings or a count of customers we do not have.

What we publish instead:

  • The deliverable formats, so you can judge the output before buying.
  • The exclusions we write into every scope, in public.
  • The failure modes we expect, on each service page.
  • Primary sources by document and version, linked so you can check them.

Start with what a penetration test report should contain, which is the standard we hold our own reporting to, and our trust centre for how we handle your data.

Questions before you book

Practical answers.

Who will actually do the work?

The senior engineers who scope your engagement stay on it to delivery. Testing is carried out by certified testers whose qualifications are listed on this page. You are not handed to a graduate after the sales call.

Why are there no names on the site?

A published name is a target and a recruiting list. We name the people on your engagement in the proposal, and we will introduce them on a call before you sign. Ask and you get CVs under NDA.

Can you show us case studies?

Not yet, and we will not manufacture them. Sorami is a new company and has no client work it can publish. What we can show is the deliverable format, the scoping method and the exclusions we write into every scope.

Will you clear our procurement requirements?

Sometimes not, and we will say so early. If your process requires a CREST member company or a supplier with a certified ISMS, we are not that firm today. We would rather tell you in week one than in week six.

What is the legal entity?

Sorami Consulting Pty Ltd, ACN 702 116 452, registered in Australia. That is the entity on every proposal and every invoice.

Let’s scope it

Want to meet the people first?

Ask for an introduction call before any proposal. We will bring the person who would run your engagement.

Request a quote

Last reviewed: