VAPT (vulnerability assessment & penetration testing)
Breadth and depth together: scanning for coverage, manual exploitation for proof.
Learn more →PentesterSpace is an ISO 27001 certified cyber security company in Bangladesh. From our office in Agargaon, Dhaka, our certified operators deliver VAPT, penetration testing, red teaming, cloud security and compliance work for banks, fintechs, SaaS products and enterprises across BD.
A cyber security company — often written cybersecurity — protects an organisation's systems, data and customers from attack. That work splits into two halves: defensive work such as monitoring, hardening and incident response, and offensive work that tests whether those defences actually hold. PentesterSpace focuses on the offensive half. We attack your systems the way a real adversary would, with permission, and hand back proof of what can be reached along with the fix. For organisations in Bangladesh this matters because regulators, enterprise customers and payment schemes increasingly ask for independent evidence that security controls have been tested, not just documented.
Nine engagement types across applications, APIs, AI systems, cloud, infrastructure and compliance.
Breadth and depth together: scanning for coverage, manual exploitation for proof.
Learn more →Grey-box testing of every user role, covering business logic and access control, not just scanner output.
Learn more →REST, GraphQL and service-to-service interfaces tested against their real behaviour.
Learn more →Android and iOS builds tested as a whole system, including the backend they talk to.
Learn more →External and internal testing that maps the path from one exposed service to real access.
Learn more →AWS, Azure and GCP configuration, pipeline and container review against provider benchmarks.
Learn more →Objective-led adversary simulation that measures detection and response, not just exploitability.
Learn more →Evidence-generating testing mapped to PCI DSS, ISO 27001, SOC 2 and HIPAA requirements.
Learn more →A Dhaka company with a local team, local contracts and support in Bangla and English.
OSCP, CREST, CRTO and eWPTXv2 holders run the engagements — not an offshore subcontractor.
ISO 27001 certified and recognised with the BASIS National ICT Award for security work.
Every finding is manually verified with reproduction steps, so nothing false reaches your engineers.
Start the engagement first. You pay once the findings and report are delivered.
Applications, APIs, cloud, infrastructure, AI systems and compliance handled by one team.
Penetration testing in Bangladesh →VAPT services in Bangladesh →Certifications & trust →
Cyber security companies in Bangladesh are concentrated mostly in Dhaka and cover penetration testing, VAPT, SOC monitoring, incident response and compliance. PentesterSpace is one of them: an ISO 27001 certified offensive security company registered in Bangladesh, with certified operators delivering manual penetration testing and red teaming for local and international clients.
Yes. PentesterSpace is a cyber security company in BD (Bangladesh), based at ICT Tower, Agargaon, Dhaka 1207. We serve organisations across BD as well as clients abroad, and all testing is performed by our own certified team.
Nine engagement types: web application, mobile application and API penetration testing, AI and LLM security testing, network and infrastructure testing, red teaming, vulnerability assessment, cloud security audit and compliance readiness assessment.
Cost depends on scope, the number of applications or hosts, and whether you need a one-time test or continuous coverage. Our pricing page lists one-time, continuous PTaaS and managed programme models, and scoping is free.
Yes. Most engagements are delivered remotely, so we work with organisations anywhere in Bangladesh and internationally. On-site work in Dhaka and elsewhere in BD can be arranged when the scope requires it.
Yes. Reports are written for auditors and engineers alike, with CVSS v3.1 ratings, reproduction steps and evidence mapped to PCI DSS, ISO 27001, SOC 2 and HIPAA requirements, plus one retest after fixes.