Start a build Book an assessment
Services Work Trust Insights Company Contact Start a build Book an assessment

Nine ways we take your systems apart — and put them back stronger.

Every service below is delivered by senior testers or engineers. Scope, deliverables and timelines are fixed before work starts, and critical findings are escalated the day they are confirmed.

Offensive security

Penetration Testing

Full-scope testing of networks, hosts and infrastructure using the same techniques a real intruder applies. We exploit what is exploitable, prove the impact, and document the path an attacker would have taken.

What we test
  • External perimeter: exposed services, VPNs, gateways, mail and DNS
  • Internal networks and assumed-breach scenarios from a compromised workstation
  • Identity: AD, Entra ID, SSO, MFA bypass, privilege escalation paths
  • Misconfigurations, unpatched services, weak credential policy
  • Pivoting, lateral movement and data-access impact
What you get
  • Executive brief and technical report
  • CVSS v4 scoring and attack-path diagrams
  • Reproduction steps and evidence for every confirmed finding
  • Remediation guidance at fix level, not policy level
  • Retest window and closure letter
2–4 weeksFixed priceNIST SP 800-115PTES
Application security

Web Application Penetration Testing

Manual application testing focused on the things automated scanning cannot see: how trust moves between users, roles and tenants, and what your business logic lets someone do that it should not.

Coverage
  • Authentication, session management, MFA and account recovery flows
  • Authorisation: IDOR, role escalation, cross-tenant access
  • Injection classes, SSRF, XXE, deserialisation, file upload
  • Business-logic abuse, race conditions, workflow bypass
  • Client-side trust: XSS, CSRF, postMessage, storage of secrets
Method
  • Manual testing against OWASP Top 10 and WSTG
  • Guided tooling (proxies, fuzzers) as support, never as the deliverable
  • Chained-exploit analysis where a low finding enables a critical one
  • Developer walkthrough session after reporting
1–3 weeksOWASP Top 10OWASP WSTGFree retest
Application security

API Penetration Testing

Your API is the product now — and usually the least supervised part of it. We test REST, GraphQL, gRPC and webhook surfaces against the OWASP API Security Top 10, with an emphasis on authorisation logic that a spec review will never catch.

Where we look
  • Broken object-level and function-level authorisation
  • Mass assignment and excessive data exposure
  • Token lifecycle: issuance, refresh, revocation, audience checks
  • Rate limiting, enumeration and abuse of unauthenticated endpoints
  • GraphQL introspection, depth abuse and resolver-level authz
  • Webhook and SSRF paths into internal services
Deliverables
  • Endpoint inventory with per-endpoint authorisation verdicts
  • Reproducible request/response evidence in a machine-readable appendix
  • Tenant-isolation report for multi-tenant platforms
  • Prioritised fix order mapped to sprint-sized work items
1–3 weeksOWASP API Top 10OpenAPI / GraphQL
AI security

LLM & AI Penetration Testing

Probabilistic systems fail in ways traditional tests do not model. We red-team your assistant, agent or RAG pipeline for prompt injection, unsafe tool use and data leakage — then tell you which controls actually reduce risk.

Attack classes
  • Direct and indirect prompt injection through user input and retrieved content
  • Jailbreak and role-play chains that defeat guardrail instructions
  • System-prompt and policy disclosure
  • Insecure tool, function and plugin invocation
  • Retrieval poisoning and cross-tenant leakage from vector stores
  • Output handling: injection into downstream renderers and code paths
  • Data exfiltration through model output and side channels
Deliverables
  • Replayable prompt corpus with success rates per attack class
  • Severity mapped to the OWASP LLM Top 10
  • Regression suite your team can run in CI after model or prompt changes
  • Control recommendations: input filtering, tool allowlists, output encoding, human gates
2–3 weeksOWASP LLM Top 10MITRE ATLAS-informed
Infrastructure

Cloud & Infrastructure Security

Most breaches in cloud environments are not exotic exploits — they are permissions, exposure and drift. We review your cloud posture as an attacker with valid access would, and then verify the findings are reachable in practice.

Review areas
  • IAM policy analysis: wildcards, trust relationships, privilege escalation paths
  • Public exposure: storage, snapshots, databases, serverless endpoints
  • Container and Kubernetes configuration, RBAC and network policy
  • Secrets sprawl across repos, images, pipelines and environment files
  • CI/CD supply chain: token scope, third-party actions, build provenance
  • Logging and detection gaps for the paths we use
Deliverables
  • Prioritised posture report with blast-radius analysis
  • Concrete policy and configuration fixes, not just rule IDs
  • IaC-ready remediation snippets for Terraform or equivalent
  • Attack-path map from initial access to sensitive data
1–2 weeksCIS BenchmarksMulti-cloud
Governance

Compliance & Audit Readiness

Testing that produces evidence your auditor accepts. We map technical findings to the controls you are being assessed against, so the same work serves security and compliance instead of being done twice.

Frameworks we support
  • ISO/IEC 27001 — Annex A technical control evidence
  • SOC 2 — security, availability and confidentiality criteria testing
  • PCI DSS v4.0 — penetration testing and segmentation requirements
  • GDPR / privacy-relevant technical controls
  • Client and insurer security questionnaires
What makes it audit-ready
  • Control-to-finding mapping with pass / partial / fail verdicts
  • Tested-scope statements and methodology references
  • Evidence retained in an auditable, timestamped form
  • Gap remediation plan with owners and target dates
2–5 weeksEvidence packAuditor liaison
Engineering security

Secure Code Review

Black-box testing finds symptoms; code review finds the cause. We review the parts of your codebase where a flaw would matter most, then wire the lessons into your pull-request process so the same class of bug stops recurring.

Focus areas
  • Authentication, session and cryptographic implementation
  • Authorisation decisions and tenant scoping in data access layers
  • Input handling, deserialisation, templating and query construction
  • Secret handling, key management and configuration hygiene
  • Third-party dependencies and unsafe library usage
Deliverables
  • File-and-line findings with suggested patches
  • SAST results triaged for real exploitability
  • Secure-coding guidance tailored to your stack
  • Optional CI rules to prevent regression
1–2 weeksLanguage agnosticPatch suggestions
Engineering

Web Application Development

Secure-by-design web products built by a team that tests them for a living. We build the customer portals, dashboards and internal tools that security teams usually inherit half-finished.

What we build
  • Customer portals, dashboards and admin consoles
  • SaaS front ends with modern component systems
  • Authentication flows: SSO, MFA, passkeys, role models
  • Integrations with your existing systems and data sources
  • Legacy rescue and incremental modernisation
How we build
  • Threat modelling before the first commit
  • Accessible, responsive interfaces as a baseline requirement
  • Automated tests and CI checks on every change
  • Pre-launch penetration test included
Project or retainerFixed-scope sprintsHandover & training
Engineering

Software Development

Custom platforms, services and automation — including the internal security tooling teams keep rebuilding by hand. Same engineers, same standards, applied to the systems your business actually runs on.

Typical work
  • Backend services, APIs and background processing
  • Data pipelines, reporting and reconciliation jobs
  • Security automation: scanning orchestration, alert triage, ticketing bridges
  • Cloud migration and infrastructure as code
  • Ongoing maintenance and reliability engineering
Engagement models
  • Discovery and architecture engagement
  • Fixed-scope delivery with defined acceptance criteria
  • Dedicated team retainer for continuous delivery
  • Team augmentation with security-aware engineers
RetainerDiscovery firstDocumented handover
Engagement models

Pick the shape that fits your team.

Point assessment

A single fixed-scope engagement: one target class, one testing window, one report and retest. Best for a release gate, a customer requirement or a first look.

Fixed price

Continuous testing

A quarterly retainer across your product surface, with regression suites, sprint-level retests and an escalation channel for anything urgent.

Quarterly

Embedded security

Our testers and engineers work alongside your delivery team: threat modelling, code review, secure design review and pre-merge security checks.

Retainer
Before you buy

What we need from you.

Penetration testing only works when authorisation and access are sorted. We send templates, but nothing starts until these are in place.

A signed statement from a person entitled to grant testing permission, naming the assets in scope. For multi-tenant or hosted systems we also need written confirmation from the platform owner.
Hostnames, IP ranges, API base URLs, environments, and anything explicitly out of bounds. Third-party services are excluded unless you have permission for us to test them.
Typically two accounts per role, plus any API keys or service accounts. Test accounts must not be shared with production users, and we ask that they are not rotated during the window.
One person reachable during testing hours who can confirm authorisation, adjust windows, and act on a critical finding the same day.
Scope at a glance

Typical shape of each engagement.

Real scope is agreed per target, but these are the ranges we quote most often. Anything outside them gets its own proposal.

ServiceTypical durationTypical teamCore deliverables
Penetration Testing2–4 weeks2 senior testersExec brief, technical report, attack paths, retest
Web Application Pentest1–3 weeks1–2 testersFindings with reproduction, CVSS v4, developer walkthrough
API Pentest1–3 weeks1–2 testersEndpoint authorisation verdicts, request/response evidence
LLM & AI Pentest2–3 weeks1 researcher + 1 testerReplayable prompt corpus, success rates, CI regression suite
Cloud & Infrastructure1–2 weeks1 consultantPosture report, blast-radius analysis, IaC-ready fixes
Compliance Readiness2–5 weeks1 lead + 1 testerControl matrix, evidence pack, remediation plan
Secure Code Review1–2 weeks1–2 reviewersFile-and-line findings, patches, CI guardrails
Web App DevelopmentSprints, 4–12 weeks2–3 engineers + designerShipped product, threat model, pre-launch pentest
Software DevelopmentRetainer or 6–16 weeks2–4 engineersDelivered services, docs, handover, support window

Not sure which service you need?

Send us the architecture diagram and a sentence about what worries you. We will recommend the smallest engagement that answers it.