Service
Pentest
We try to get into what you asked us to protect and we record the path. If the flaw does not open, it does not become a cover finding. The report is for engineering to reproduce and for leadership to decide what closes first.
What is in
- Web, API, mobile, infra and cloud in the agreed slice
- Exploitation and chaining, not only tool alerts
- Critical issues raised mid-test when the risk asks for it
- A report with reproduction, impact and priority
- A conversation after delivery and a retest of what was closed
What is out
- A scan sold as a pentest
- The whole environment without looking at the size
- On-site work
- A 5-day pack with a price locked in the first email
Who it is for
- A release or a large change in the application
- A customer or audit asking for an offensive test
- An environment that was never really exploited
- An ongoing contract, with a new slice each cycle
How it runs
From the call to the report
01
Call
What needs protecting, what stays untouched, the deadline, one-off or ongoing.
02
Scope
Written surface: URLs, apps, accounts, test users and limits.
03
Exploitation
Recon, entry attempts and chaining until impact.
04
Delivery
Report, fix order and, if you ask, a retest.
What we test
Authentication, session, authorization across users and tenants, business logic, injection, IDOR, upload, SSRF, payment flows and the API behind the app. Mobile includes local storage and what the binary gives away. Infra and cloud: exposed services, identity and what an initial credential unlocks.
The limit is written down. Without it the test becomes theatre or an incident. With it, the team knows what was looked at and what stayed out.
How the report is written
Problem title, precondition, steps, impact on data or an account, and what to close. A score alone does not prioritize a sprint. A tool alert that did not hold leaves the hot list.
An exploitable critical does not wait for the PDF. The window channel exists for that.
One-off and ongoing
A single shot fits when the object is still: this release, this tenant. An ongoing cycle fits when the product ships every week and the cloud gains a role mid-quarter. Each cycle has a new slice.
Questions on this page
How is pentest different from a scan?
A scan lists what looks weak. A pentest tries to exploit and shows the path. Alert count is not coverage.
Will the test take production down?
The exercise is controlled. We exploit to validate impact, inside what was authorized. Critical production and hours go into scope before we start.
How long does it take?
It depends on the surface. A small API and a ten-year ERP do not share a timeline. That comes from the meeting.
Next step
Want to book a meeting?
Tell us the company size and what needs to be protected — the system, the environment, what is at stake. From the call, we assess the scenario and build the work within your scope.