The practice

Small on purpose.

Stonegate Defense exists because too many security reports are written by someone who never touched the network, for a client who never gets to speak to the person who did. We kept the firm small so that cannot happen.

Adam Austin, founder and principal consultant of Stonegate Defense Adam Austin · Founder & Principal

Founder

Adam Austin

Twenty years in technology, and a NITRO-certified practitioner. Founder and principal consultant at Stonegate Defense.

Two decades spent building, running, and eventually breaking systems produces a particular instinct: most breaches are not clever. They are a forgotten host, an over-permissioned service account, a credential reused between a test environment and a production one, or a monitoring gap that nobody noticed because nothing had ever tripped it. The exotic zero-day makes the news; the boring misconfiguration makes the incident.

That is what Stonegate Defense is built to find — and, more importantly, to help you actually close. A finding that stays open for eight months because nobody owned it is not meaningfully different from a finding nobody ever made.

Adam handles engagements personally, from the scoping call through the report walkthrough and the retest. When a specialist is genuinely needed, that is said plainly and arranged — rather than covered up by a generalist billing at specialist rates.

  • Twenty years in technology — systems, networks, and security operations across the full lifecycle.
  • NITRO-certified — certification maintained in current practice.
  • One accountable principal — the person who scopes it tests it, writes it, and presents it.
  • Based in Alabama — engagements delivered remotely nationwide, on site by arrangement.

How we work

Four things you can hold us to.

Evidence, not adjectives

Nothing is called critical without a demonstration of why. If we cannot show impact, it goes in the report as an observation with the uncertainty stated — not dressed up to pad a severity count. A report full of theoretical highs trains your team to ignore the real ones.

Authorization before anything

Written scope, written rules of engagement, written authorization to test, and a named escalation contact — before a single packet. We will not test an asset you cannot demonstrate the right to authorize, including systems your vendor operates on your behalf.

The boring truth, on time

If your environment is in decent shape, the report will say so and the invoice will not grow to justify itself. If you do not need the engagement you asked for, we will tell you that during scoping, before you have spent anything.

The job ends at the fix

Remediation guidance written for your stack, a walkthrough with the engineers doing the work, availability while they do it, and a retest to confirm it landed. Delivery of a PDF is a milestone, not a conclusion.

Fit

Who we're a good fit for.

Organizations large enough to have something worth stealing and small enough that security is somebody's second job: professional services firms, healthcare and dental practices, credit unions and community banks, manufacturers, municipal and county agencies, software companies filling in their first serious client security questionnaire, and any business whose insurer has started asking harder questions at renewal.

We are also a good fit if you already have a security team and want an outside perspective that will disagree with them in writing when the evidence supports it.

Who we're not

We do not sell software, take vendor referral fees, or resell tools we then recommend. There is no product on the other end of the assessment, which is precisely why you can trust what the assessment says. And we do not take engagements against systems the client cannot demonstrate authority over — no exceptions, regardless of how the request is framed.

Policy

Responsible disclosure

If you have found a security issue in Stonegate Defense's own infrastructure, we want to hear about it and we will not come after you for telling us.

  • Report it to security@stonegatedefense.com, or see /.well-known/security.txt.
  • We acknowledge reports and keep you updated until the issue is resolved.
  • Please give us a reasonable window to fix it before publishing.
  • Do not access, modify, or exfiltrate data that is not yours, and do not degrade the service for anyone else.
  • Good-faith research within these bounds will not result in legal action from us.

Findings in client environments

Vulnerabilities we discover in third-party or vendor products during client engagements are disclosed to the vendor coordinated with the client, on a reasonable timeline, and never published with client details attached.

Client identities, findings, and evidence are confidential by default and are not used in marketing — which is why you will not find a logo wall on this site.

Emergency

Reading this during an incident?

Skip the rest of the site. Isolate what you can, leave it powered on, and get in touch.

Next step

Start with a conversation.

Tell us what the environment looks like and what is keeping you up. We will tell you what a useful engagement would be — or that you do not need one yet.