Services
Everything we test, and who it's for.
From a quick launch check to a full SaaS assurance engagement. Every service is run by a certified tester, follows published standards, and ends in a report you can act on and share.
01 · Web · API
Web & API Penetration Testing
SaaS products and web apps where a breach means customer data or money.
What we test
- —OWASP WSTG and API Security Top 10
- —Authorisation & IDOR, tested as every role
- —Authentication, session, tokens and MFA
- —Injection, XSS, SSRF, XXE, upload abuse
- —Business logic: payment, replay, limits
You get: Plain-English report with fixes, retest, and an attestation letter.
02 · Android · iOS
Mobile App Testing
Teams shipping an Android or iOS app that handles accounts or payments.
What we test
- —OWASP MASTG coverage
- —Local storage, keychain and secrets
- —API and backend communication
- —Certificate pinning and tampering
- —Reverse-engineering resistance
You get: Per-platform findings with fixes, plus a retest.
03 · Infra · PTES
External Network & Attack Surface
Anyone with servers, VPNs or services exposed to the internet.
What we test
- —Full external attack-surface mapping
- —Exposed services and misconfigurations
- —TLS, patching and known CVEs
- —Credential and exposure checks
- —Email security (SPF, DKIM, DMARC)
You get: Prioritised exposure report with remediation steps.
04 · AWS · Azure · GCP · M365
Cloud & Microsoft 365 Review
Teams on cloud infra or Microsoft 365 that have never had it reviewed.
What we test
- —CIS Benchmark configuration review
- —IAM, roles and over-privilege
- —Storage, network and secrets exposure
- —Logging, monitoring and backups
- —M365 tenant and identity hardening
You get: Config review mapped to CIS, with a fix checklist.
05 · Web + API + Cloud
SaaS Assurance Bundle
SaaS companies that need one engagement covering the whole stack for a customer or audit.
What we test
- —Everything in web, API and cloud testing
- —End-to-end, across every user role
- —Mapped to SOC 2, ISO 27001 and DPDP
- —Executive readout for stakeholders
You get: Full report, compliance mapping, two retests and an attestation letter.
06 · Ongoing · Monthly
Security Retainer
Teams shipping fast who want security checked continuously, not once a year.
What we test
- —Testing of new features as they ship
- —Monthly attack-surface monitoring
- —A named tester on call for questions
- —Priority retests and advisories
You get: Rolling findings and a monthly summary.
07 · SOC 2 · ISO 27001 · DPDP
Compliance Readiness
Companies getting audit-ready for a customer or a certification.
What we test
- —Gap assessment against the framework
- —Technical controls, tested not just documented
- —Evidence and policy guidance
- —Pre-audit readiness review
You get: Readiness report, gap list and the pentest auditors expect.
08 · People · Awareness
Phishing Simulation & Training
Teams whose biggest risk is a staff member clicking the wrong link.
What we test
- —Realistic phishing campaign
- —Click, credential and report rates
- —Live awareness training session
- —Tailored guidance for your tools
You get: Results report and a staff training session.
09 · Consumer
Personal & Family Security
Individuals and families who want their accounts and devices made safe.
What we test
- —Personal security checkup (1 hr)
- —Hacked-account recovery
- —Family online-safety session
- —Password, MFA and device hardening
You get: A clear checklist and hands-on help.
Not sure which you need?
Tell us about your stack and we'll recommend a scope and a fixed price in 24 hours.