Methodology
How we test, and what you get.
Every engagement follows published standards, is run by a certified tester, and ends in a plain-English report you can act on and share. AI speeds up recon and reporting; a person confirms every finding before it reaches you.
Standards
The frameworks your auditors expect.
Web applications
The Web Security Testing Guide — the standard checklist for web app testing.
APIs
The common, high-impact API risks: broken object- and function-level authorisation, and more.
Mobile apps
The Mobile Application Security Testing Guide for Android and iOS.
Network & infra
The Penetration Testing Execution Standard for external and internal network work.
Technical testing
The US standard for planning and conducting security assessments.
Cloud & M365
Consensus hardening baselines for AWS, Azure, GCP and Microsoft 365.
The engagement
Five stages, no surprises.
Scope
A short form fixes the price and the targets. Nothing outside it is touched.
Authorise
Signed scope and rules of engagement — the legal line before any test.
Test
Hands-on testing by a certified tester. Critical findings reach you the same day.
Report
Plain-English findings with fixes, mapped to your framework.
Retest
We re-check your fixes and issue a retest certificate.
What we check
Depth where it matters.
- 01Recon and mapping — every page, parameter and API endpoint, and the tech stack
- 02Authentication and session — login, reset, MFA, tokens, timeouts, brute-force
- 03Authorisation — the core SaaS test: IDOR and role boundaries, run as every role
- 04Input handling — injection, cross-site scripting, SSRF, XXE, file-upload abuse
- 05Business logic — skipping payment, replaying requests, abusing limits and coupons
- 06API Top 10 — object- and function-level authorisation, mass assignment, rate limits
- 07Configuration and exposure — cloud, headers, secrets, and anything indexed that should not be
Severity
How we rate findings.
Scored with CVSS v3.1 (or v4.0 on request), then adjusted for real business impact.
| Rating | CVSS | What it means | How you hear about it |
|---|---|---|---|
| Critical | 9.0–10.0 | Direct takeover or mass data exposure, easy to exploit | Phone call the same day |
| High | 7.0–8.9 | Serious access or data exposure with some conditions | In the next status email |
| Medium | 4.0–6.9 | Needs chaining or has limited impact | In the report |
| Low | 0.1–3.9 | Hardening and hygiene | In the report |
| Informational | — | Good practice, no direct risk | In the report |
The deliverable
What every report contains.
- —A one-page executive summary in plain language, mapped to your framework
- —A findings table, sorted by severity, to scan at a glance
- —Per finding: description, affected asset, steps to reproduce, masked evidence, impact, CVSS and a concrete fix
- —A compliance mapping page (SOC 2 / ISO 27001 / DPDP) when you need one
- —A retest certificate showing what was fixed
- —An attestation letter your customers and auditors will accept
Want to judge the real thing? A redacted sample report is the best way — request it and we'll send it over.
Get a fixed quote in 24 hours.
Or run a free exposure snapshot — no login, no obligation.