Penetration testing
Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.
- Deliverable
- Findings report · retest
- Stages
- 4
- Pricing
- Fixed, agreed before start
A time-boxed, scope-bounded assessment run by named operators. Automated tooling is used where it earns its place — coverage, enumeration, regression — but the findings that matter come from manual analysis of your authorisation model, your trust boundaries, and the assumptions your code makes about its own inputs. Every finding arrives reproducible, with a working proof of concept and remediation your developers can act on without a translation layer.
How the engagement runs
- 01
Reconnaissance and mapping
Full enumeration of the attack surface inside scope: routes, parameters, roles, dependencies, and the boundaries between them. The map, not the scanner output, drives everything after it.
- 02
Manual exploitation
Testing against the application logic — authorisation, state, tenancy, trust in client-supplied data — alongside the injection and deserialisation classes. Anything critical reaches you the hour it is confirmed.
- 03
Post-exploitation and impact
Each confirmed issue is chased to its real business impact rather than reported at its theoretical severity. A reflected parameter that reaches an admin session is not a medium.
- 04
Reporting and retest
Findings are written up as they are confirmed, not batched at the end. Once you have shipped fixes we verify them and reissue the report.
Typical scope
- Web applications and single-page front ends
- REST, GraphQL and gRPC APIs
- Internal and external network infrastructure
- Cloud configuration and identity boundaries
- Mobile applications (Android, iOS)
- Authentication, session and multi-tenancy logic

