Services
Services
Every service runs under an agreed scope and written authorisation. We propose only the testing approach that genuinely fits your systems and your risk.
- 01
Web application penetration testing
Predominantly manual testing aligned to the OWASP Web Security Testing Guide, including the business-logic flaws automated scanners cannot detect.
- What we test
- The in-scope web applications, authenticated and unauthenticated, including core business workflows, session handling and every level of access control.
- How we test
- Predominantly manual testing aligned to the OWASP Web Security Testing Guide. Tooling assists discovery; business-logic flaws are found by hand because scanners cannot see them.
- What you receive
- A report with evidence, reproduction steps, CVSS ratings and specific remediation guidance for each finding, followed by retesting after fixes.
- Business value
- Lower likelihood of a data breach through the application your customers and partners actually use, and testing evidence for auditors and contractual requirements.
- Access control and horizontal / vertical privilege escalation
- Injection, cross-site scripting, SSRF and deserialisation flaws
- Business logic defects and bypassable workflow steps
- 02
API security testing
REST, GraphQL and gRPC testing referencing the OWASP API Security Top 10, focused on object-level and property-level authorisation.
- What we test
- The in-scope REST, GraphQL and gRPC services, covering authentication, object- and property-level authorisation, and resource consumption limits.
- How we test
- Testing referenced to the OWASP API Security Top 10 from multiple user roles, combining schema and documentation analysis with manual request manipulation.
- What you receive
- An endpoint-by-endpoint report with reproducible sample requests, the data exposure at stake, and design-level recommendations where needed.
- Business value
- Prevents cross-account data access and API abuse — the most common root cause of breaches in modern architectures.
- Broken object level and function level authorisation
- Excessive data exposure and mass assignment
- Rate limiting and unrestricted resource consumption
- 03
Mobile application security testing
Android and iOS testing following OWASP MASVS and MASTG, covering the client, its transport and the services behind it.
- What we test
- The in-scope Android and iOS apps: local data storage, transport, the back-end services the app calls, and resistance to reverse engineering.
- How we test
- Static and dynamic testing following OWASP MASVS and MASTG on real devices and emulators, with the app’s APIs tested alongside the client.
- What you receive
- A report that maps each finding to MASVS requirements with severity, evidence and platform-specific remediation.
- Business value
- Protects user data on devices you do not control, and gives you evidence for app-store and third-party review requirements.
- Local data storage and cryptographic key handling
- Transport security and certificate validation
- Platform interaction and resilience against reverse engineering
- 04
Internal infrastructure penetration testing
Simulates an attacker who is already on the network, to show how they would escalate privilege and move towards critical systems.
- What we test
- The in-scope internal network, Active Directory, servers, workstations and internal services — from the position of someone who already has network access.
- How we test
- An assumed-breach simulation covering discovery, privilege escalation and lateral movement, under strict, agreed rules of engagement.
- What you receive
- Proven attack paths from starting point to target, the points at which each path can be cut, and a prioritised remediation order.
- Business value
- Know how far an attacker or malware could travel from a single compromised machine, and where to stop them before they reach critical systems.
- Privilege escalation and lateral movement paths
- Active Directory and internal service misconfiguration
- Network segmentation and trust boundary validation
- 05
External infrastructure penetration testing
Assesses everything your organisation exposes to the internet, from the position of an attacker with no access at all.
- What we test
- The in-scope internet-facing assets: IP ranges, domains, exposed services, VPN endpoints and login interfaces.
- How we test
- External attack-surface discovery, identification of exposed services and insecure configuration, and manual confirmation of findings without disrupting live services.
- What you receive
- An external attack-surface map, confirmed vulnerabilities with evidence, and recommendations for reducing what is unnecessarily exposed.
- Business value
- Removes the entry points external attackers rely on and gives you a current picture of what your organisation exposes to the internet.
- Exposed services and insecure configuration
- Login interfaces, VPN and remote access services
- Information disclosure and unnecessary exposure
- 06
Cloud configuration and security assessment
Review of cloud account configuration, entitlements and resource isolation against each provider’s own documented guidance.
- What we test
- The in-scope cloud accounts and projects: identity and access management, storage, virtual networking, logging and environment isolation.
- How we test
- Configuration review against each provider’s own documented guidance, combined with manual analysis of privilege escalation paths.
- What you receive
- A risk-ordered report of unsafe configuration, the escalation paths found, and policy-level remediation guidance.
- Business value
- Prevents data exposure from misconfiguration — the leading cause of cloud incidents — and limits the cost of resources being abused.
- Over-broad permission policies and escalation paths
- Unintentionally reachable storage and key material
- Logging, monitoring and environment separation
- 07
Source code security review
Reading the code alongside dynamic testing to find the root cause of a vulnerability rather than only its symptom.
- What we test
- The in-scope application source or components: input handling, authentication, secret management and use of cryptographic libraries.
- How we test
- Reviewer-led code reading supported by static analysis, confirmed with dynamic testing where possible to keep false positives out of the report.
- What you receive
- Findings pinned to code locations with root cause, recurring patterns, and secure code examples for the fix.
- Business value
- Fixes the cause rather than the symptom, reduces the same class of bug reappearing, and raises the development team’s practice.
- Data flow tracing from untrusted input to sensitive sink
- Recurring code patterns that keep producing the same class of bug
- Review of cryptographic library usage and secret handling
- 08
Vulnerability validation
Triage of automated scanner output: false positives removed, and only genuinely exploitable issues confirmed.
- What we test
- The output of vulnerability scanners or third-party reports named in scope.
- How we test
- Each item reproduced by hand in the authorised environment, false positives removed, and real exploitability assessed in your context.
- What you receive
- A confirmed list with evidence, severity adjusted for context, and the items removed together with the reason.
- Business value
- Your team spends its time on real risk instead of chasing thousands of tool-generated entries.
- Exploitability confirmed inside an authorised environment
- Prioritisation based on real impact to your systems
- Less engineering time lost chasing false positives
- 09
Remediation consultation
Working with your engineering and infrastructure teams to design fixes that are practical for the architecture you actually have.
- What we test
- Findings from our testing or someone else’s, together with the architecture the fix has to live in.
- How we test
- Working sessions with your development and infrastructure teams to design fixes that fit the systems you have, reviewed before implementation.
- What you receive
- Written recommendations, remediation options with their trade-offs, and the criteria used to confirm a fix worked.
- Business value
- Faster, correct-first-time remediation, fewer retest cycles, and less risk left open while fixes are pending.
- Root cause explained alongside the remediation options
- Review of the fixes your team proposes
- Interim mitigations where a permanent fix is not yet possible
- 10
Penetration test retesting
Retesting of remediated findings to confirm the fix works and has not introduced a new weakness.
- What we test
- The findings from a previous report that have been reported as fixed.
- How we test
- Each finding tested again with the original method and close variants, to confirm the weakness is closed and nothing new was introduced.
- What you receive
- A closure report stating the status of every finding (fixed, partially fixed, not fixed) with fresh evidence.
- Business value
- Credible evidence for leadership, auditors and partners that the reported risk has been dealt with.
- Finding-by-finding verification with fresh evidence
- Checks that the fix did not open new attack surface
- A closure report suitable for governance and audit files
If your engagement does not map neatly onto the list below, get in touch to discuss scope. We will tell you plainly if the work falls outside our expertise.
Contact
Start with a scoping conversation
Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.
We test only with written authorisation and only within the agreed scope.