Every attack surface you ship, tested by hand.
Six specialised practice areas, one delivery model. Pick the assets that need testing, or scope a combined engagement across all of them.
Every surface you ship, tested by hand.
Pick one asset type or all six — the scope drives the price, and nothing is bundled that you don't need.
Role-aware web testing and REST/GraphQL API coverage, including undocumented routes.
- OWASP Top 10 + logic flaws
- REST & GraphQL endpoint testing
- Multi-role authz + rate limits
iOS and Android binaries plus their backend APIs.
- Static and runtime analysis
- Local storage and keychain
- Certificate pinning bypass
Internal or external hosts, on-prem or hosted.
- Service and version exposure
- Credential and lateral paths
- Segmentation checks
AWS, Azure and GCP account review.
- IAM privilege escalation
- Public storage and secrets
- Logging and guardrails
Phishing and pretext campaigns with consent.
- Targeted phishing waves
- MFA fatigue attempts
- Awareness reporting
Full adversary simulation testing detection, response and resilience.
- Multi-stage attack chains
- Detection and response gaps
- MITRE ATT&CK mapping
Every practice area, in detail.
Each page covers scope, features, methodology, sample findings, and specialty FAQs.
Role-aware web testing and REST/GraphQL API coverage, including undocumented routes.
- OWASP Top 10 + logic flaws
- REST & GraphQL endpoint testing
- Multi-role authz + rate limits
iOS and Android binaries plus their backend APIs.
- Static and runtime analysis
- Local storage and keychain
- Certificate pinning bypass
Internal or external hosts, on-prem or hosted.
- Service and version exposure
- Credential and lateral paths
- Segmentation checks
AWS, Azure and GCP account review.
- IAM privilege escalation
- Public storage and secrets
- Logging and guardrails
Phishing and pretext campaigns with consent.
- Targeted phishing waves
- MFA fatigue attempts
- Awareness reporting
Full adversary simulation testing detection, response and resilience.
- Multi-stage attack chains
- Detection and response gaps
- MITRE ATT&CK mapping
Not sure which surfaces apply to you?
Start the scoping form. It walks you through the questions your auditor is going to ask, and produces a quote at the end.
