Penetration testing
Manual testing of your applications and networks, with proof of impact and a fix for every finding.
What the engagement covers.
Web applications
Authentication, session handling, access control, injection, business logic abuse, and the parts a scanner cannot reason about.
APIs
REST and GraphQL endpoints tested for broken object-level authorization, mass assignment, rate limiting gaps, and data exposure.
Mobile applications
iOS and Android clients, local storage, certificate pinning, and the backend calls they make.
External infrastructure
Everything reachable from the internet: exposed services, forgotten hosts, mail and DNS configuration, and credential reuse.
Internal networks
Assumed-breach testing from a standard workstation. Active Directory paths, lateral movement, and what a phished employee's laptop reaches.
Authenticated and unauthenticated
We test as an anonymous visitor, as each role you give us, and as a customer trying to reach another customer's data.
How it runs.
Scope
Targets, roles, test accounts, exclusions, and windows agreed in writing. Rules of engagement signed before anything is touched.
Test
Consultants work the scope by hand. Critical findings are reported the day they are confirmed, not held for the report.
Report
Reproduction steps, evidence, risk rating, and a concrete fix for every finding, plus a summary written for leadership.
Retest
After fixes ship, every finding is verified again and the report is updated. This is included, not billed separately.
What you receive.
- Technical report with reproduction steps and evidence
- Executive summary with business impact
- Remediation guidance per finding, ranked by exploitability
- Retest report and closure letter for auditors and customers
Who it is for.
- Products preparing for SOC 2, ISO 27001, or PCI DSS assessment
- Teams shipping a new customer-facing platform or API
- Companies asked by a customer to provide a recent pentest report
Questions about penetration testing.
How long does a penetration test take?
Most web or API engagements take one to three weeks of testing, followed by a week for reporting. Internal network tests are usually two weeks. We confirm the estimate during scoping and hold the dates.
Do you test in production or staging?
Either. Production gives the truest result; staging is safer when downtime is costly. If we test staging, we confirm parity with production first and note any differences in the report.
What do you need from us to start?
A list of targets, test accounts for each role, a technical contact for the testing window, and signed authorization. We provide the templates.
Scope a penetration testing engagement.
Tell us about the system and the deadline. You will get a fixed-price proposal after one scoping call.