Independent offensive security

We break your systems on a schedule, so nobody else does it on theirs.

Security Test Service runs manual, evidence-driven penetration tests across twenty disciplines — web and mobile applications, APIs, internal and external networks, cloud and container estates, staff, premises, and full adversary simulation. Every finding arrives with reproduction steps, a CVSS v4.0 score, and a fix you can actually ship.

CREST-aligned methodology · OSCP / CRTO / GWAPT-certified testers · Retest included

Engagement snapshotEXAMPLE
Assessment
Web app + API, grey box
Scope
2 domains · 148 endpoints
Test window
8 business days
Standards
OWASP ASVS 4.0 L2
Findings
1 critical · 4 high · 9 medium
Report delivered
Day 11
Free retest by
Day 90

Tested against

  • OWASP ASVS
  • OWASP MASVS
  • PTES
  • NIST SP 800-115
  • MITRE ATT&CK
  • CIS Benchmarks
  • OSSTMM
  • PCI DSS 4.0 §11.4
  • ISO 27001 A.8.8
  • SOC 2 CC7.1

Why teams bring us in

Scanners find patterns. People find business logic.

Automated tooling gets you to the starting line. Everything past it — chained privilege escalation, broken authorization between tenants, a workflow that lets a user approve their own refund — takes a human who understands what your application is for.

Manual-first testing

Tooling handles coverage and enumeration. Exploitation, chaining, and business-logic abuse are done by hand by a named tester you can talk to directly.

Findings you can act on

Every issue ships with request/response evidence, a reproduction path, affected assets, and a concrete remediation — not a CVE number and a link.

No surprise invoices

Fixed-price engagements scoped before kickoff. Remediation retests inside 90 days are included, and so is the attestation letter your customers ask for.

Safe by design

Rules of engagement agreed in writing, destructive tests excluded unless explicitly authorised, out-of-hours windows available, and a live escalation channel throughout.

Test catalog · 20 disciplines

Every kind of cyber testing, under one engagement

Buy a single assessment or combine several into one scope and one report. Codes below are the reference identifiers used in your statement of work.

Application Security

APP · 5 services
APP-01

Web Application Penetration Testing

Authenticated, multi-role testing of your web application for injection, broken access control, authentication and session flaws, SSRF, insecure deserialization, and business-logic abuse that scanners cannot reason about.

OWASP Top 10ASVS L1–L3Grey / white box
APP-02

API & Web Services Testing

REST, GraphQL, gRPC and SOAP endpoints tested for broken object-level and function-level authorization, mass assignment, rate-limit bypass, token replay, and schema introspection leakage.

OWASP API Top 10OpenAPI-drivenBOLA / BFLA
APP-03

Mobile Application Testing

iOS and Android binaries assessed on-device: insecure local storage, keychain and keystore misuse, certificate pinning bypass, exported components, runtime manipulation, and backend API exposure.

OWASP MASVSJailbreak / rootStatic + dynamic
APP-04

Secure Source Code Review

Manual review of authentication, authorization, cryptography, input handling and secrets management in your codebase, guided by static analysis but validated line by line to remove the false positives.

SAST-assistedLanguage-agnosticDependency audit
APP-05

Thick Client & Desktop Testing

Installed Windows, macOS and Linux applications tested for insecure IPC, DLL hijacking, hardcoded credentials, local privilege escalation, and unprotected client-server protocols.

Binary analysisTraffic interceptionPrivilege escalation

Network & Infrastructure

NET · 4 services
NET-01

External Network Penetration Testing

Your internet-facing perimeter mapped and attacked the way an unauthenticated outsider would: exposed services, unpatched edge devices, VPN and mail misconfiguration, forgotten hosts, and credential exposure.

Black boxAttack-surface mappingNIST SP 800-115
NET-02

Internal Network Penetration Testing

Starting from a standard workstation or network drop, we model the attacker who is already inside: lateral movement, relay and poisoning attacks, credential harvesting, and the path to domain compromise.

Assumed breachLateral movementSegmentation check
NET-03

Active Directory Security Assessment

Focused review of AD and Entra ID: delegation abuse, Kerberoasting and AS-REP roasting, ACL misconfiguration, certificate services (ADCS) escalation paths, tiering failures, and stale privileged accounts.

ADCS pathsKerberos abuseHybrid identity
NET-04

Wireless Network Testing

802.11 estates assessed for weak WPA2/WPA3 configuration, PMKID and handshake capture, EAP misconfiguration, rogue and evil-twin access points, and guest-to-corporate network bleed.

WPA2 / WPA3802.1X / EAPRogue AP detection

Cloud, Container & Pipeline

CLD · 3 services
CLD-01

Cloud Configuration Review

AWS, Azure and Google Cloud tenancies reviewed against CIS Foundations: over-permissive IAM roles and trust policies, public storage, unencrypted data stores, absent logging, and privilege-escalation paths between services.

AWS / Azure / GCPCIS FoundationsIAM escalation
CLD-02

Container & Kubernetes Testing

Cluster and image security end to end: RBAC review, privileged workloads and host mounts, container escape paths, admission-control gaps, secrets handling, and registry image composition.

Kubernetes RBACContainer escapeImage scanning
CLD-03

CI/CD & Software Supply Chain Assessment

Build pipelines assessed for poisoned dependencies, unsigned artifacts, over-scoped runner credentials, workflow injection, branch-protection bypass, and secrets leaking through build logs.

SLSA levelsSBOM reviewRunner isolation

People & Premises

HUM · 2 services
HUM-01

Social Engineering & Phishing Simulation

Targeted phishing, vishing and SMS campaigns built from real open-source reconnaissance, measuring click, credential-submission and report rates — plus whether your detection and response actually fired.

Phishing / vishingMFA fatigueAwareness metrics
HUM-02

Physical Security Assessment

Authorised attempts to enter your premises: tailgating, badge cloning, lock and door bypass, reception pretexting, and what an intruder can reach once inside — unlocked workstations, network ports, printed data.

RFID cloningTailgatingClean-desk audit

Adversary Simulation

ADV · 3 services
ADV-01

Red Team Operations

A goal-oriented, multi-week campaign against a defined objective — cardholder data, source code, the finance system — using stealth, custom tooling and any combination of digital, physical and human vectors.

MITRE ATT&CKObjective-basedCovert
ADV-02

Purple Team Exercises

Attack techniques executed side by side with your defenders, one at a time, to measure exactly which detections fire, which alerts are triaged, and which ATT&CK techniques pass through unseen.

Detection coverageSIEM tuningCollaborative
ADV-03

Ransomware Readiness & Assumed Breach

A safe, non-destructive simulation of ransomware operator tradecraft — initial foothold, discovery, credential theft, backup targeting and staged exfiltration — to test containment before it is tested for you.

Non-destructiveBackup resilienceExfil simulation

Emerging & Specialised

SPC · 3 services
SPC-01

IoT & Embedded Device Testing

Hardware and firmware assessed together: debug interfaces (UART/JTAG), firmware extraction and analysis, hardcoded keys, insecure update mechanisms, and the radio and cloud channels the device talks over.

Firmware analysisUART / JTAGBLE / Zigbee
SPC-02

OT / ICS & SCADA Assessment

Passive-first testing of industrial environments — asset discovery, protocol and segmentation review, Purdue-model validation, and safe evaluation of PLC and HMI exposure without touching production control.

IEC 62443Purdue modelPassive discovery
SPC-03

AI & LLM Application Testing

Testing for prompt injection (direct and indirect), tool and function-call abuse, training and retrieval data leakage, insecure output handling, and excessive agency in agentic workflows and RAG pipelines.

OWASP LLM Top 10Prompt injectionAgent tooling

How an engagement runs

Six phases, agreed in writing before anyone touches a keyboard

The sequence below is fixed. What changes between engagements is depth, duration and the rules of engagement we set with you in phase one.

01

Scoping & authorisation

Targets, exclusions, test windows, emergency contacts and destructive-test limits are agreed and signed. You get a fixed price and a start date.

02

Reconnaissance & mapping

Open-source intelligence, asset discovery and full enumeration of the in-scope attack surface, including assets you may not know you own.

03

Vulnerability discovery

Automated coverage plus manual analysis to identify weaknesses, with every candidate finding verified by hand before it goes near the report.

04

Exploitation & chaining

Controlled exploitation to prove real impact, then chaining low-severity issues into the escalation paths that actually threaten the business.

05

Reporting & debrief

Report delivered within three business days of test close, followed by a live walkthrough for engineering and a separate summary for leadership.

06

Remediation retest

Once you have shipped fixes, we retest every finding and reissue the report with updated status — included free within 90 days of delivery.

What you actually receive

A report your engineers use and your auditors accept

Severity bands & notification commitments
SeverityCVSS v4.0You are told
Critical9.0 – 10.0Immediately, by phone
High7.0 – 8.9Within 4 hours
Medium4.0 – 6.9In the report
Low0.1 – 3.9In the report
Informational0.0Appendix

Critical findings are escalated the moment they are confirmed — we do not sit on them until report day.

  • Executive summaryTwo pages of business risk and posture, written for people who will never read a payload.
  • Technical findingsAffected assets, full reproduction steps, request/response evidence, and CVSS v4.0 vector strings.
  • Prioritised remediation planOrdered by exploitability and business impact, with specific fixes rather than generic advice.
  • Machine-readable findingsCSV, JSON and Jira-ready exports so issues land in your backlog without retyping.
  • Retest reportEvery finding re-verified after your fixes, with closed/open status and residual risk.
  • Attestation letterA shareable, one-page letter of testing for customers, insurers and auditors — no confidential detail.

Before you ask

Common questions

How long does a typical test take?

A single web application is usually five to ten business days of testing. External network tests run three to five days. Red team operations run three to six weeks. We give you an exact duration and price at scoping, before you commit.

Will testing take our production systems down?

No. Denial-of-service and other destructive techniques are excluded by default and only run against a staging environment with explicit written authorisation. High-volume activity can be scheduled outside business hours, and you have a live escalation contact throughout.

Black box, grey box or white box?

Grey box gives most organisations the best value: we get credentials and documentation, so time goes into finding flaws rather than guessing at the application. Black box better simulates an outsider; white box with source access finds the most per day spent.

Who actually performs the test?

Named, in-house senior testers holding OSCP, OSWE, CRTO, GWAPT or equivalent certifications. Nothing is subcontracted or offshored, and you can speak to your tester directly during the engagement.

Does this satisfy our compliance requirement?

Our engagements map to PCI DSS 4.0 requirement 11.4, ISO 27001 control A.8.8, SOC 2 CC7.1 and HIPAA §164.308(a)(8). The attestation letter and report are written so assessors accept them as evidence.

How is our data handled?

All evidence is stored encrypted in a dedicated tenancy, restricted to the engagement team, and destroyed on a schedule you set — 30, 90 or 180 days after report delivery. NDAs are signed before scoping begins.

How often should we test?

Annually as a floor, and after any significant architectural change, new external service, or acquisition. Teams shipping continuously typically move to quarterly application testing with continuous external attack-surface monitoring between engagements.

What do you need from us to start?

A list of in-scope targets, a signed authorisation form, test credentials for each user role, and a technical point of contact. For cloud reviews we also need read-only audit access. Most engagements start within two weeks of scoping.

Start here

Tell us what you want tested. We'll tell you what it takes.

Scoping calls run about thirty minutes and cost nothing. You leave with a recommended test type, a duration, and a fixed price — whether or not you go ahead with us.

PLACEHOLDER CONTACT DETAILS — replace the email addresses and the phone number above (and in the two buttons) with your live details before publishing.