Services

Services

Every service runs under an agreed scope and written authorisation. We propose only the testing approach that genuinely fits your systems and your risk.

  • 01

    Web application penetration testing

    Predominantly manual testing aligned to the OWASP Web Security Testing Guide, including the business-logic flaws automated scanners cannot detect.

    What we test
    The in-scope web applications, authenticated and unauthenticated, including core business workflows, session handling and every level of access control.
    How we test
    Predominantly manual testing aligned to the OWASP Web Security Testing Guide. Tooling assists discovery; business-logic flaws are found by hand because scanners cannot see them.
    What you receive
    A report with evidence, reproduction steps, CVSS ratings and specific remediation guidance for each finding, followed by retesting after fixes.
    Business value
    Lower likelihood of a data breach through the application your customers and partners actually use, and testing evidence for auditors and contractual requirements.
    • Access control and horizontal / vertical privilege escalation
    • Injection, cross-site scripting, SSRF and deserialisation flaws
    • Business logic defects and bypassable workflow steps
  • 02

    API security testing

    REST, GraphQL and gRPC testing referencing the OWASP API Security Top 10, focused on object-level and property-level authorisation.

    What we test
    The in-scope REST, GraphQL and gRPC services, covering authentication, object- and property-level authorisation, and resource consumption limits.
    How we test
    Testing referenced to the OWASP API Security Top 10 from multiple user roles, combining schema and documentation analysis with manual request manipulation.
    What you receive
    An endpoint-by-endpoint report with reproducible sample requests, the data exposure at stake, and design-level recommendations where needed.
    Business value
    Prevents cross-account data access and API abuse — the most common root cause of breaches in modern architectures.
    • Broken object level and function level authorisation
    • Excessive data exposure and mass assignment
    • Rate limiting and unrestricted resource consumption
  • 03

    Mobile application security testing

    Android and iOS testing following OWASP MASVS and MASTG, covering the client, its transport and the services behind it.

    What we test
    The in-scope Android and iOS apps: local data storage, transport, the back-end services the app calls, and resistance to reverse engineering.
    How we test
    Static and dynamic testing following OWASP MASVS and MASTG on real devices and emulators, with the app’s APIs tested alongside the client.
    What you receive
    A report that maps each finding to MASVS requirements with severity, evidence and platform-specific remediation.
    Business value
    Protects user data on devices you do not control, and gives you evidence for app-store and third-party review requirements.
    • Local data storage and cryptographic key handling
    • Transport security and certificate validation
    • Platform interaction and resilience against reverse engineering
  • 04

    Internal infrastructure penetration testing

    Simulates an attacker who is already on the network, to show how they would escalate privilege and move towards critical systems.

    What we test
    The in-scope internal network, Active Directory, servers, workstations and internal services — from the position of someone who already has network access.
    How we test
    An assumed-breach simulation covering discovery, privilege escalation and lateral movement, under strict, agreed rules of engagement.
    What you receive
    Proven attack paths from starting point to target, the points at which each path can be cut, and a prioritised remediation order.
    Business value
    Know how far an attacker or malware could travel from a single compromised machine, and where to stop them before they reach critical systems.
    • Privilege escalation and lateral movement paths
    • Active Directory and internal service misconfiguration
    • Network segmentation and trust boundary validation
  • 05

    External infrastructure penetration testing

    Assesses everything your organisation exposes to the internet, from the position of an attacker with no access at all.

    What we test
    The in-scope internet-facing assets: IP ranges, domains, exposed services, VPN endpoints and login interfaces.
    How we test
    External attack-surface discovery, identification of exposed services and insecure configuration, and manual confirmation of findings without disrupting live services.
    What you receive
    An external attack-surface map, confirmed vulnerabilities with evidence, and recommendations for reducing what is unnecessarily exposed.
    Business value
    Removes the entry points external attackers rely on and gives you a current picture of what your organisation exposes to the internet.
    • Exposed services and insecure configuration
    • Login interfaces, VPN and remote access services
    • Information disclosure and unnecessary exposure
  • 06

    Cloud configuration and security assessment

    Review of cloud account configuration, entitlements and resource isolation against each provider’s own documented guidance.

    What we test
    The in-scope cloud accounts and projects: identity and access management, storage, virtual networking, logging and environment isolation.
    How we test
    Configuration review against each provider’s own documented guidance, combined with manual analysis of privilege escalation paths.
    What you receive
    A risk-ordered report of unsafe configuration, the escalation paths found, and policy-level remediation guidance.
    Business value
    Prevents data exposure from misconfiguration — the leading cause of cloud incidents — and limits the cost of resources being abused.
    • Over-broad permission policies and escalation paths
    • Unintentionally reachable storage and key material
    • Logging, monitoring and environment separation
  • 07

    Source code security review

    Reading the code alongside dynamic testing to find the root cause of a vulnerability rather than only its symptom.

    What we test
    The in-scope application source or components: input handling, authentication, secret management and use of cryptographic libraries.
    How we test
    Reviewer-led code reading supported by static analysis, confirmed with dynamic testing where possible to keep false positives out of the report.
    What you receive
    Findings pinned to code locations with root cause, recurring patterns, and secure code examples for the fix.
    Business value
    Fixes the cause rather than the symptom, reduces the same class of bug reappearing, and raises the development team’s practice.
    • Data flow tracing from untrusted input to sensitive sink
    • Recurring code patterns that keep producing the same class of bug
    • Review of cryptographic library usage and secret handling
  • 08

    Vulnerability validation

    Triage of automated scanner output: false positives removed, and only genuinely exploitable issues confirmed.

    What we test
    The output of vulnerability scanners or third-party reports named in scope.
    How we test
    Each item reproduced by hand in the authorised environment, false positives removed, and real exploitability assessed in your context.
    What you receive
    A confirmed list with evidence, severity adjusted for context, and the items removed together with the reason.
    Business value
    Your team spends its time on real risk instead of chasing thousands of tool-generated entries.
    • Exploitability confirmed inside an authorised environment
    • Prioritisation based on real impact to your systems
    • Less engineering time lost chasing false positives
  • 09

    Remediation consultation

    Working with your engineering and infrastructure teams to design fixes that are practical for the architecture you actually have.

    What we test
    Findings from our testing or someone else’s, together with the architecture the fix has to live in.
    How we test
    Working sessions with your development and infrastructure teams to design fixes that fit the systems you have, reviewed before implementation.
    What you receive
    Written recommendations, remediation options with their trade-offs, and the criteria used to confirm a fix worked.
    Business value
    Faster, correct-first-time remediation, fewer retest cycles, and less risk left open while fixes are pending.
    • Root cause explained alongside the remediation options
    • Review of the fixes your team proposes
    • Interim mitigations where a permanent fix is not yet possible
  • 10

    Penetration test retesting

    Retesting of remediated findings to confirm the fix works and has not introduced a new weakness.

    What we test
    The findings from a previous report that have been reported as fixed.
    How we test
    Each finding tested again with the original method and close variants, to confirm the weakness is closed and nothing new was introduced.
    What you receive
    A closure report stating the status of every finding (fixed, partially fixed, not fixed) with fresh evidence.
    Business value
    Credible evidence for leadership, auditors and partners that the reported risk has been dealt with.
    • Finding-by-finding verification with fresh evidence
    • Checks that the fix did not open new attack surface
    • A closure report suitable for governance and audit files

If your engagement does not map neatly onto the list below, get in touch to discuss scope. We will tell you plainly if the work falls outside our expertise.

Contact

Start with a scoping conversation

Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.

We test only with written authorisation and only within the agreed scope.