Web applications and portals
Authenticated and unauthenticated testing against the OWASP Top 10 and OWASP ASVS, including business-logic flaws that no scanner will ever find.
Offensive Security
Vulnerability assessment finds what is wrong. Penetration testing proves what an attacker could do with it. We run both, verify every finding by hand, and stay on the engagement until the fixes hold.
VAPT is two pieces of work that are usually sold as one. The vulnerability assessment is broad: it sweeps everything in scope and produces a list. The penetration test is deep: it takes the interesting items from that list and establishes whether they can be chained into something that genuinely hurts. You need both, because breadth without depth gives you a spreadsheet of theoretical risk, and depth without breadth means you tested the three things somebody remembered to mention.
The failure mode we see most often is a 300-page report that is really a tool export with a cover page. Every open port, every missing header, every informational notice, sorted by CVSS and handed over. Nobody reads it. Nothing gets fixed. The next year it is regenerated with a new date.
We do it the other way round. Automation gives us coverage — our engine carries 10,046 detection rules and matches findings against 356,454 CVEs scored by real exploit probability, so nothing obvious is missed. Then a person goes through the candidates, discards the noise, confirms what is genuinely exploitable, and works out what it means for your business. What you receive is short, ranked, and every item in it is real.
Coverage
Scope is agreed in writing before anything starts. Most clients begin with one or two of these and widen once they have seen a report.
Authenticated and unauthenticated testing against the OWASP Top 10 and OWASP ASVS, including business-logic flaws that no scanner will ever find.
REST, GraphQL and internal service-to-service interfaces, tested against the OWASP API Security Top 10 — broken object-level authorisation is still the single most common critical we report.
Android and iOS binaries and their backends, assessed against the OWASP MASVS, including local storage, certificate handling and hardcoded secrets.
External perimeter and internal segments: exposed services, patch state, weak authentication, and lateral movement paths once a foothold exists.
AWS, Azure and GCP configuration, identity and permission review against CIS benchmarks and the provider’s own well-architected guidance.
Manual review of authentication, authorisation, cryptography, input handling and secrets management, alongside automated analysis across 27 languages and runtimes.
Domain configuration, privilege paths, delegation and credential hygiene — the assessment that most often changes how an internal network is run.
Corporate wireless, guest segregation and the network ports in the reception area everybody forgets about.
Approach
The shape of the work follows PTES and NIST SP 800-115. What we do not publish is the internals — payloads, sequencing and tooling chains stay with the engine.
We agree targets, testing windows, rules of engagement and escalation contacts, then get written authorisation. Production systems get out-of-hours windows if load is a concern.
We map the real attack surface — the subdomains, staging environments and forgotten services that are not on the asset list you sent us. This is where roughly a third of critical findings originate.
Broad automated coverage across the agreed scope, matched against current vulnerability intelligence, with known-exploited flaws escalated on sight rather than by score.
A human confirms each candidate, establishes real impact, and chains issues where chaining is possible. Anything critical is reported the same day we confirm it — you do not wait for the report.
One document with an executive summary, a ranked technical section, evidence and reproduction steps, control mappings and a fix for every finding.
A walkthrough call with your engineers, then a free retest once fixes are deployed. The report records the state change per finding, so you have a defensible before-and-after.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Two pages a non-technical director can read: what the risk is in business terms, what it would cost you, and what to do first.
Each with CVSS, exploit probability, affected asset and version, evidence, reproduction steps and a specific fix — not "apply vendor patches".
Every finding mapped to ISO 27001 Annex A, PCI DSS, HIPAA, NIST CSF and OWASP ASVS clauses, so remediation doubles as audit evidence.
A POA&M-style tracker with owners and target dates, in a format your project managers can actually work from.
SARIF and JSON alongside PDF and HTML, so findings load straight into your code-scanning dashboard or ticket queue.
A clean summary after the retest, suitable for handing to a customer, auditor or board.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
A vulnerability assessment identifies and catalogues weaknesses across everything in scope — it is broad, largely automated, and answers "what might be wrong here?". A penetration test takes those weaknesses and attempts to exploit them the way an attacker would, to establish what is genuinely reachable and what the real business impact is. VAPT means running both, so you get coverage and proof rather than one or the other.
A single web application is typically five to eight working days of testing, plus two to three days for reporting. A network perimeter of under 50 hosts is usually a week. Larger programmes covering multiple applications, internal networks and cloud environments run three to six weeks. We give you a firm number in the written scope before you commit, not a range that moves later.
No. Testing that could affect availability — anything resembling denial of service, or high-volume automated activity — is excluded by default and only runs if you specifically ask for it in writing. Production testing is scheduled in agreed windows, we monitor as we go, and there is a named escalation contact on both sides for the duration.
Whichever gives you a truthful answer. Staging is safer but is rarely configured identically to production, and configuration is where a large share of real findings live. Our usual recommendation is staging for the intrusive parts and production for a controlled, agreed subset. We will tell you plainly what each choice costs you in coverage.
Yes. One retest cycle is included in every engagement at no extra cost. You fix, we verify, and the report records the state change per finding rather than becoming a new document with no history.
We issue a summary letter after the retest confirming the scope tested, the dates, and the closure status of findings. It is written to be shared with customers, auditors and procurement teams without exposing technical detail that should stay private.
Yes. The team holds industry certifications across offensive security and cloud, and the founding team brings over 20 years of combined experience across cybersecurity, cloud, compliance and enterprise technology. We are happy to share individual credentials under NDA during scoping.
It depends almost entirely on scope — the number of applications, the size of the network, whether testing is authenticated, and whether you need retesting and remediation support. Rather than publish a number that would be wrong for you, we scope in a 30-minute call and send a written fixed price. Most first engagements with SMEs and startups land in a range that is materially below what the large consultancies quote for the same work.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.