Find what your
scanners miss.
Manual penetration testing across web, mobile, network, and APIs. We don't just run scans — we chain vulnerabilities, build proofs-of-concept, and write reports your engineers can act on.
Scope
What we test.
Hands-on testing across four areas. Pick one for a focused engagement or combine for a full-coverage audit.
Web applications
OWASP Top 10, business-logic flaws, authentication & authorisation bypasses, session handling, injection chains.
Mobile applications
iOS and Android. OWASP MASVS-aligned. Static and dynamic analysis, runtime instrumentation, IPC abuse, insecure storage.
Network infrastructure
External perimeter, internal network, wireless. Service enumeration, exploit chaining, lateral movement, privilege escalation.
APIs
REST, GraphQL, gRPC. Schema review, authentication abuse, parameter pollution, BOLA and business-logic attacks.
Methodology
How we work.
Scoping & threat modelling
We map the assets in scope, understand your threat model, and agree rules of engagement before any traffic hits production.
Reconnaissance & enumeration
Discover the attack surface — assets, technologies, configurations, authentication paths, third-party dependencies.
Vulnerability identification
Manual hunting backed by tooling. We look for chained issues, not just isolated CVEs your scanners already flagged.
Exploitation
Validate findings with reproducible proofs-of-concept. The goal is to demonstrate impact, not just presence.
Reporting & retest
Executive summary, technical detail, remediation guidance. Retest after your team has shipped the fixes.
Deliverables
What you receive.
Everything you need to fix what we found — and prove it to your auditors.
Download sample report PDF- Executive summary (1–2 page PDF for leadership and auditors)
- Technical findings report with reproduction steps and evidence
- Risk-prioritised remediation plan with concrete next steps
- Live debrief and Q&A with your engineering team
- Retest after fixes are shipped (typically within 30 days)
- Compliance-ready report formatting on request (SOC 2, ISO 27001, PCI DSS)
FAQs
Common questions.
01 How long does a typical engagement take?
Most engagements run 2–4 weeks of testing depending on scope. A focused web application audit is around 2 weeks; a multi-tier network or full mobile + API combo can take 4–6 weeks. A scoping call usually narrows this to within a few days.
02 What do you need from us to scope an engagement?
A rough description of the target (asset count, tech stack, what authentication looks like) and your goals (compliance audit, pre-launch readiness, recurring quarterly). We can scope from a 30-minute call.
03 Onsite or remote?
Remote by default. Onsite is available for internal-network engagements or when your threat model requires it — travel billed separately.
04 Do you provide a report suitable for compliance audits?
Yes. The standard report is technical-first, but we produce a clean executive summary and can format findings to align with SOC 2, ISO 27001, or PCI DSS expectations.
05 What happens to critical findings discovered mid-engagement?
Anything critical or high-severity is reported to your security contact within 24 hours, separately from the final report — your team can start fixing before testing wraps up.