Penetration testing · Network, web, mobile, API
Penetration testing that proves real risk.
A senior tester scopes the work with your engineers, tests by hand, and reports findings the day they surface. You get exploitable risk ranked by impact, not a scanner export.
Recon · Why it matters
A scanner finds patterns. A tester finds a way in.
Automated tools flag what looks wrong. They cannot chain a weak session token to an exposed admin route and turn it into account takeover. That chaining is where real breaches come from, and it is what we test for. Every finding we report has been reproduced by hand and rated on what an attacker could actually do with it.
Coverage · What we test
What is in scope.
01
Network and infrastructure
External perimeter, internal segmentation, Active Directory, VPN and remote access, wireless.
02
Web applications
Authentication and session handling, access control between roles and tenants, injection, and the business logic that only breaks when you use it the way an attacker would.
03
APIs
REST and GraphQL endpoints, authorisation on every object, rate limiting, and data exposure in responses the interface never shows.
04
Mobile
iOS and Android clients, local storage, certificate handling, and the backend they talk to.
Execution · How we work
How the engagement runs.
Step 01
Scoping
Thirty minutes with your technical team. We agree targets, depth, test windows, and what is off limits. No blind testing.
Step 02
Testing with daily updates
You get a direct channel to your tester. Critical findings reach you the day we find them, not in a report three weeks later.
Step 03
Reporting
Written for the engineers who will fix it: reproduction steps, proof of concept, impact, and a fix-first order.
Step 04
Retest
We validate your fixes at no extra cost and state clearly what is closed and what is not.
Debrief · What you get
What lands on your desk.
Every engagement ends with something your engineers can act on and your auditors can accept.
- Technical report with reproduction steps and proof of concept for every finding
- Executive summary a board or a client can read without translation
- Remediation roadmap ordered by exploitability, not by severity label alone
- Retest and attestation once your fixes land, suitable for auditors and clients
Questions · Straight answers
Common questions.
How long does a penetration test take?
Most engagements run five to ten days from kickoff to report, depending on scope. Scoping itself takes a single call, and we can usually start within days rather than weeks.
Do you test production systems?
Often yes, with agreed windows and safeguards. Where availability cannot be risked, we test a staging environment that mirrors production and review the differences with you.
Is a retest included?
Yes. Validating your fixes is part of the engagement, not a separate invoice.
Need this scoped? Let's talk.
Tell us what you need tested and when. A senior tester reads every request and replies within an hour with scope, timing and price.
Reply within an hour · NDA on request · Scoped by a senior tester, not sales