Penetration testing and security assessments.
Manual, scope-driven testing of the systems your customers rely on. Each engagement is defined before it starts, performed only against authorized targets and reported so that engineers, security leads and auditors can act on it.
- SVC-0101
Web Application Penetration Testing
Manual testing of the application your customers actually use.
Manual, scope-driven testing of authentication, authorization, session handling, business logic and injection classes in modern web applications and single-page apps.
Web Application Pentesting detailsIdeal for
- B2B SaaS platforms with multi-tenant data
- Applications preparing for or maintaining SOC 2
- Products facing enterprise security questionnaires
- Teams shipping frequently that need release validation
- SVC-0202
API Penetration Testing
REST and GraphQL testing focused on authorization and data exposure.
Manual testing of REST and GraphQL APIs for object- and function-level authorization, token handling, mass assignment, excessive data exposure and API abuse.
API Pentesting detailsIdeal for
- SaaS products with public or partner APIs
- Mobile back ends and single-page application APIs
- AI products exposing inference or data endpoints
- Platforms with customer-facing API keys or OAuth apps
- SVC-0303
Network Penetration Testing
External attack surface and internal network testing, scoped by your Rules of Engagement.
External testing of your internet-facing attack surface and internal testing of your corporate or production network, including Active Directory where applicable.
Network Pentesting detailsIdeal for
- Companies with public infrastructure beyond a single web app
- Organizations with an office or corporate network and directory services
- PCI DSS programs requiring external and internal testing
- Teams validating segmentation between environments
- SVC-0404
Cloud Security Assessment
Identity, exposure and configuration review for AWS, Azure and GCP environments.
Assessment of cloud identity and access, public exposure, storage, network configuration and secrets handling across AWS, Azure and GCP — scoped during pre-engagement.
Cloud Security detailsIdeal for
- Cloud-native SaaS running on AWS, Azure or GCP
- Teams without a dedicated cloud security engineer
- Companies answering enterprise questions about cloud configuration
- Organizations combining application and infrastructure testing
Around the core engagements.
Smaller or recurring pieces of work that complement a penetration test. Scoped the same way, reported the same way.
- SVC-05
Security Assessments
Targeted assessments of a component, feature or architecture when a full penetration test is not the right fit.
More - SVC-06
Retesting / Remediation Verification
Verification that remediated findings are fixed, with updated retest results for your report and evidence program.
More - SVC-07
Application Security Testing
Security testing integrated with your release cycle — new features, major changes and pre-release validation.
More - SVC-08
Infrastructure Security Testing
Testing of servers, services and supporting infrastructure that sit behind or beside your application.
More - SVC-09
Compliance-supporting testing
Penetration testing scoped so that the results can be used as technical evidence in SOC 2, PCI DSS, NIST or CIS Controls programs.
More
Scope first. Authorization second. Testing third.
Every engagement starts with a consultation and a written scope: targets, environments, roles, exclusions, testing window and exploitation limits, captured in the Rules of Engagement. Testing is performed only against explicitly authorized targets.
Request a security assessment.
Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.