Skip to content

Penetration testing

Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.

Deliverable
Findings report · retest
Stages
4
Pricing
Fixed, agreed before start

A time-boxed, scope-bounded assessment run by named operators. Automated tooling is used where it earns its place — coverage, enumeration, regression — but the findings that matter come from manual analysis of your authorisation model, your trust boundaries, and the assumptions your code makes about its own inputs. Every finding arrives reproducible, with a working proof of concept and remediation your developers can act on without a translation layer.

How the engagement runs

  1. 01

    Reconnaissance and mapping

    Full enumeration of the attack surface inside scope: routes, parameters, roles, dependencies, and the boundaries between them. The map, not the scanner output, drives everything after it.

  2. 02

    Manual exploitation

    Testing against the application logic — authorisation, state, tenancy, trust in client-supplied data — alongside the injection and deserialisation classes. Anything critical reaches you the hour it is confirmed.

  3. 03

    Post-exploitation and impact

    Each confirmed issue is chased to its real business impact rather than reported at its theoretical severity. A reflected parameter that reaches an admin session is not a medium.

  4. 04

    Reporting and retest

    Findings are written up as they are confirmed, not batched at the end. Once you have shipped fixes we verify them and reissue the report.

Typical scope

  • Web applications and single-page front ends
  • REST, GraphQL and gRPC APIs
  • Internal and external network infrastructure
  • Cloud configuration and identity boundaries
  • Mobile applications (Android, iOS)
  • Authentication, session and multi-tenancy logic

Other engagements