Penetration testing that your auditor, your board and your engineers can all read.
Manual, scoped testing against your web applications, APIs, cloud estate and internal network — delivered with the evidence needed to close a SOC 2 control and the detail needed to actually fix the issue.
- Typical duration
- 8–12 days
- Lead time
- 2–3 weeks
- Deliverables
- Report, attestation letter, retest
- Standards
- OWASP ASVS 4.0, PTES
What we test
Credential handling, MFA bypass, session fixation, token rotation
Horizontal and vertical privilege escalation, IDOR, tenant isolation
Workflow abuse, race conditions, pricing and quota manipulation
Injection, deserialisation, file upload, SSRF
How a finding is written
Broken access control on /api/v1/users
Any authenticated user can read another tenant's user records by substituting the account identifier. No authorisation check is performed against the requesting session.
1GET /api/v1/users/42 HTTP/1.12Host: api.acme.io3Authorization: Bearer eyJhbGciOi…45HTTP/1.1 200 OK6{"id":42,"email":"cfo@othertenant.com"}
Enforce tenant scope in the data access layer rather than the controller, and add a regression test asserting a 403 for cross-tenant identifiers.
Five stages, no surprises
A 30-minute call and a short worksheet. You get a fixed price and dates.
Estate mapping, credential provisioning, threat modelling against your architecture.
Manual testing by a named engineer. Criticals are reported the day we find them.
Findings, evidence, remediation guidance, and an executive summary that is actually one page.
90 days to remediate. We re-verify and reissue the report and attestation letter.

