Penetration testing services.
Seven engagement types across applications, APIs, AI systems and infrastructure. Every engagement is scoped in writing before it starts, run by a certified operator, and closed with a retest.
Scope an engagement →Web Application Pentest
Grey-box testing with credentials for every role you want covered. Business logic and access control get the same attention as the injection classes a scanner finds.
- Scope
- Authenticated and unauthenticated paths, each user role and tenant boundary, session handling, password reset and MFA flows, file upload and export, and any admin surface you include.
- Method
- OWASP WSTG, with manual exploitation and chaining. Scanner output is used for coverage, never reported without validation.
- Deliverable
- Findings rated with CVSS v3.1, each with reproduction steps, request and response evidence, and remediation notes written for engineers. One retest after fixes.
Mobile Application Pentest
Android and iOS builds tested as a whole system: the compiled app, what it writes to the device, and the backend it talks to.
- Scope
- Static and dynamic analysis of the build, local storage and keychain use, certificate pinning and traffic interception, IPC, deep links and exported components. Backend APIs included by agreement.
- Method
- OWASP MASVS on rooted and jailbroken devices, plus a stock device where a control only holds on unmodified platforms.
- Deliverable
- One report per platform, with the device and OS version each finding was reproduced on. Retest after fixes.
API Pentest
REST, GraphQL and service-to-service interfaces tested against their real behaviour, including endpoints the specification does not mention.
- Scope
- Object and function level authorisation per role, authentication and token handling, mass assignment, injection, rate limiting and resource consumption. GraphQL introspection, depth and batching where applicable.
- Method
- OWASP API Security Top 10. The provided OpenAPI or GraphQL schema is reviewed first, then compared against what the API actually accepts.
- Deliverable
- Findings with the exact requests that reproduce them, ready to replay. Retest after fixes.
AI & LLM Pentest
Model-backed features tested as attack surface: the prompts, the tools the model can call, the data it retrieves, and the agents that chain them.
- Scope
- Direct and indirect prompt injection, system prompt extraction, tool invocation and excessive agency, retrieval and embedding poisoning, output handling in downstream systems, and cost or quota abuse.
- Method
- OWASP Top 10 for LLM Applications and MITRE ATLAS, tested against the running application rather than the model in isolation.
- Deliverable
- Findings with the prompts and payloads that trigger them, and the downstream impact each one produced. Retest after fixes.
Network & Infra Pentest
External or internal, or both. The goal is the path from one exposed service to the access that actually matters.
- Scope
- Host and service discovery, patch and configuration weaknesses, default and reused credentials, network segmentation, and privilege escalation and lateral movement from an assumed foothold.
- Method
- NIST SP 800-115 and PTES. Exploitation is agreed in the rules of engagement before testing starts.
- Deliverable
- Findings with affected hosts, the path taken, and remediation ordered by what closes the most exposure. Retest after fixes.
Red Teaming Exercises
An objective-led exercise against your live environment. It measures detection and response as much as exploitability, so it suits teams that already run a SOC.
- Scope
- Agreed objectives such as reaching a system, a dataset or a level of access. Initial access, persistence, privilege escalation and exfiltration paths, within the constraints set in the rules of engagement.
- Method
- Techniques mapped to MITRE ATT&CK. Every action is timestamped and logged so your team can reconstruct the timeline afterwards.
- Deliverable
- Attack narrative with the ATT&CK mapping, a detection gap analysis against what your tooling recorded, and a purple team debrief.
Vulnerability Assessment
Breadth over depth. Useful when you need regular coverage of a large estate rather than deep exploitation of one application.
- Scope
- Authenticated and unauthenticated scanning across the hosts and applications in the agreed inventory, on a one-off or recurring schedule.
- Method
- Automated scanning with manual triage. Every finding is verified by an operator before it reaches you, so false positives do not become tickets.
- Deliverable
- Prioritised findings with CVSS scores, plus a comparison against the previous cycle showing what was fixed, what regressed and what is still open.