Nine ways we take your systems apart — and put them back stronger.
Every service below is delivered by senior testers or engineers. Scope, deliverables and timelines are fixed before work starts, and critical findings are escalated the day they are confirmed.
Full-scope testing of networks, hosts and infrastructure using the same techniques a real intruder applies. We exploit what is exploitable, prove the impact, and document the path an attacker would have taken.
What we test
External perimeter: exposed services, VPNs, gateways, mail and DNS
Internal networks and assumed-breach scenarios from a compromised workstation
Reproduction steps and evidence for every confirmed finding
Remediation guidance at fix level, not policy level
Retest window and closure letter
2–4 weeksFixed priceNIST SP 800-115PTES
Application security
Web Application Penetration Testing
Manual application testing focused on the things automated scanning cannot see: how trust moves between users, roles and tenants, and what your business logic lets someone do that it should not.
Coverage
Authentication, session management, MFA and account recovery flows
Authorisation: IDOR, role escalation, cross-tenant access
Client-side trust: XSS, CSRF, postMessage, storage of secrets
Method
Manual testing against OWASP Top 10 and WSTG
Guided tooling (proxies, fuzzers) as support, never as the deliverable
Chained-exploit analysis where a low finding enables a critical one
Developer walkthrough session after reporting
1–3 weeksOWASP Top 10OWASP WSTGFree retest
Application security
API Penetration Testing
Your API is the product now — and usually the least supervised part of it. We test REST, GraphQL, gRPC and webhook surfaces against the OWASP API Security Top 10, with an emphasis on authorisation logic that a spec review will never catch.
Where we look
Broken object-level and function-level authorisation
Rate limiting, enumeration and abuse of unauthenticated endpoints
GraphQL introspection, depth abuse and resolver-level authz
Webhook and SSRF paths into internal services
Deliverables
Endpoint inventory with per-endpoint authorisation verdicts
Reproducible request/response evidence in a machine-readable appendix
Tenant-isolation report for multi-tenant platforms
Prioritised fix order mapped to sprint-sized work items
1–3 weeksOWASP API Top 10OpenAPI / GraphQL
AI security
LLM & AI Penetration Testing
Probabilistic systems fail in ways traditional tests do not model. We red-team your assistant, agent or RAG pipeline for prompt injection, unsafe tool use and data leakage — then tell you which controls actually reduce risk.
Attack classes
Direct and indirect prompt injection through user input and retrieved content
Jailbreak and role-play chains that defeat guardrail instructions
System-prompt and policy disclosure
Insecure tool, function and plugin invocation
Retrieval poisoning and cross-tenant leakage from vector stores
Output handling: injection into downstream renderers and code paths
Data exfiltration through model output and side channels
Deliverables
Replayable prompt corpus with success rates per attack class
Severity mapped to the OWASP LLM Top 10
Regression suite your team can run in CI after model or prompt changes
Control recommendations: input filtering, tool allowlists, output encoding, human gates
2–3 weeksOWASP LLM Top 10MITRE ATLAS-informed
Infrastructure
Cloud & Infrastructure Security
Most breaches in cloud environments are not exotic exploits — they are permissions, exposure and drift. We review your cloud posture as an attacker with valid access would, and then verify the findings are reachable in practice.
Review areas
IAM policy analysis: wildcards, trust relationships, privilege escalation paths
Public exposure: storage, snapshots, databases, serverless endpoints
Container and Kubernetes configuration, RBAC and network policy
Secrets sprawl across repos, images, pipelines and environment files
Prioritised posture report with blast-radius analysis
Concrete policy and configuration fixes, not just rule IDs
IaC-ready remediation snippets for Terraform or equivalent
Attack-path map from initial access to sensitive data
1–2 weeksCIS BenchmarksMulti-cloud
Governance
Compliance & Audit Readiness
Testing that produces evidence your auditor accepts. We map technical findings to the controls you are being assessed against, so the same work serves security and compliance instead of being done twice.
Frameworks we support
ISO/IEC 27001 — Annex A technical control evidence
SOC 2 — security, availability and confidentiality criteria testing
PCI DSS v4.0 — penetration testing and segmentation requirements
GDPR / privacy-relevant technical controls
Client and insurer security questionnaires
What makes it audit-ready
Control-to-finding mapping with pass / partial / fail verdicts
Tested-scope statements and methodology references
Evidence retained in an auditable, timestamped form
Gap remediation plan with owners and target dates
2–5 weeksEvidence packAuditor liaison
Engineering security
Secure Code Review
Black-box testing finds symptoms; code review finds the cause. We review the parts of your codebase where a flaw would matter most, then wire the lessons into your pull-request process so the same class of bug stops recurring.
Focus areas
Authentication, session and cryptographic implementation
Authorisation decisions and tenant scoping in data access layers
Input handling, deserialisation, templating and query construction
Secret handling, key management and configuration hygiene
Third-party dependencies and unsafe library usage
Deliverables
File-and-line findings with suggested patches
SAST results triaged for real exploitability
Secure-coding guidance tailored to your stack
Optional CI rules to prevent regression
1–2 weeksLanguage agnosticPatch suggestions
Engineering
Web Application Development
Secure-by-design web products built by a team that tests them for a living. We build the customer portals, dashboards and internal tools that security teams usually inherit half-finished.
What we build
Customer portals, dashboards and admin consoles
SaaS front ends with modern component systems
Authentication flows: SSO, MFA, passkeys, role models
Integrations with your existing systems and data sources
Legacy rescue and incremental modernisation
How we build
Threat modelling before the first commit
Accessible, responsive interfaces as a baseline requirement
Automated tests and CI checks on every change
Pre-launch penetration test included
Project or retainerFixed-scope sprintsHandover & training
Engineering
Software Development
Custom platforms, services and automation — including the internal security tooling teams keep rebuilding by hand. Same engineers, same standards, applied to the systems your business actually runs on.
Fixed-scope delivery with defined acceptance criteria
Dedicated team retainer for continuous delivery
Team augmentation with security-aware engineers
RetainerDiscovery firstDocumented handover
Engagement models
Pick the shape that fits your team.
Point assessment
A single fixed-scope engagement: one target class, one testing window, one report and retest. Best for a release gate, a customer requirement or a first look.
Fixed price
Continuous testing
A quarterly retainer across your product surface, with regression suites, sprint-level retests and an escalation channel for anything urgent.
Quarterly
Embedded security
Our testers and engineers work alongside your delivery team: threat modelling, code review, secure design review and pre-merge security checks.
Retainer
Before you buy
What we need from you.
Penetration testing only works when authorisation and access are sorted. We send templates, but nothing starts until these are in place.
A signed statement from a person entitled to grant testing permission, naming the assets in scope. For multi-tenant or hosted systems we also need written confirmation from the platform owner.
Hostnames, IP ranges, API base URLs, environments, and anything explicitly out of bounds. Third-party services are excluded unless you have permission for us to test them.
Typically two accounts per role, plus any API keys or service accounts. Test accounts must not be shared with production users, and we ask that they are not rotated during the window.
One person reachable during testing hours who can confirm authorisation, adjust windows, and act on a critical finding the same day.
Scope at a glance
Typical shape of each engagement.
Real scope is agreed per target, but these are the ranges we quote most often. Anything outside them gets its own proposal.