Penetration testing
Penetration testing and vulnerability assessment
Find and close security gaps before they are exploited. Our testing is done manually by practitioners and focuses on real business risk, not just scanner output.
01
Types of testing
Automated scanners miss business logic flaws. We add manual exploitation so findings reflect the real risk.
01
Web applications
In-depth testing of web portals, ERP and SaaS applications, including authentication, authorisation and business logic.
02
Android apps
Static and dynamic analysis of the APK: data storage, communication, authentication and protection bypass, to OWASP MASVS.
03
iOS apps
Testing of iPhone and iPad apps: keychain use, jailbreak detection, certificate pinning and client-side logic.
04
Desktop applications
Windows and thick-client apps: server communication, stored credentials, DLL handling and reverse engineering.
05
APIs
Making sure API endpoints are safe from data manipulation, injection and unauthorised access.
06
Network infrastructure
Simulated attacks on servers, routers and firewalls from inside and outside.
07
VPN and remote access
VPN gateways, RDP and other remote access: configuration, authentication, MFA and the lateral-movement risk once connected.
08
Social engineering
Phishing simulations to measure staff security awareness, with written approval.
02
Methodology
Reconnaissance
Map the attack surface within the agreed scope.
Vulnerability analysis
An initial scan followed by manual verification.
Exploitation
Controlled, realistic attack simulation without damaging production systems.
Reporting and debrief
Executive and technical reports, then a walkthrough with your team.
Retest
Fixed findings are tested again and their status confirmed in writing.
03
What you receive
- An executive summary management can follow
- Technical findings with CVSS scores, evidence and reproduction steps
- Remediation guidance your developers can act on
- A retest letter after remediation
- Evidence that supports ISO/IEC 27001 audits and UU PDP obligations
04
Secure your applications and infrastructure
Tell us which systems you want tested, the environment (production or staging) and your deadline. We will propose a scope and schedule.
Discuss your pentest


