What we test
- Web applications and APIs. Authentication and session management, access control, injection, business-logic abuse, file handling, third-party integrations; REST and GraphQL APIs; single-page applications. Methodology: OWASP Web Security Testing Guide (WSTG v4.2), with OWASP ASVS as the checklist for coverage.
- External network. Your internet-facing footprint: exposed services, VPNs, mail, DNS, certificate hygiene, forgotten hosts. Methodology: PTES.
- Internal network and Active Directory. What an attacker with a foothold or a malicious insider can reach: segmentation, credential hygiene, privilege escalation paths, lateral movement.
- Cloud configuration. Identity and access, storage exposure, network paths, logging and secrets management on the major public clouds.
- Mobile applications. IOS and Android apps and the APIs behind them, following the OWASP Mobile Application Security guides.
How we test
Manual first. Tooling (scanners, proxies, fuzzers) is used to save time on the obvious, and findings it produces are verified by hand before they appear in a report. We chain findings to demonstrate real impact rather than listing severities in isolation, and we stop and call you when we reach something that should not be touched further.
Rules of engagement are written and signed: written authority from the asset owner, scope, exclusions, allowed techniques, test windows, data handling, safety and stop rules, emergency contacts. No denial-of-service, no social engineering unless it is a red team engagement, no exploitation beyond what is needed to prove impact. Testing reduces risk; it does not guarantee that no vulnerability remains, and it does not remediate on your behalf.
After the test
Findings feed straight into remediation — ours if you use Secure Engineering or CaaS, or your team’s with our support. The retest verifies the agreed findings within the agreed window, and the test-completion statement gives procurement what it needs — it is not a certification or a regulatory attestation, and testing cannot show that no other issue exists.