Every test they can ask you for.
Offensive Testing
- VAPTFull-scope vulnerability assessment and penetration testing
- Web Application TestingOWASP ASVS-aligned testing for web apps and SPAs
- API Penetration TestingREST, GraphQL and gRPC - authorization and logic flaws
- Mobile App TestingiOS and Android, binary analysis to backend APIs
- Network Penetration TestingExternal, internal and Active Directory attack paths
- Cloud Configuration ReviewAWS, Azure and GCP reviewed against the CIS Benchmarks
- Red TeamingAdversary simulation against detection and response
Assurance & Compliance
FAQ
Choosing a service
Which service do we actually need?
Most teams start with the thing their customers or auditors are asking about, which is usually the web application and its API. If you are not sure, describe what you build on a scoping call and we will tell you what is worth testing and what is not - including when the answer is a smaller engagement than you expected.
Can several services be combined in one engagement?
Yes, and it is usually cheaper than running them separately because the reconnaissance is shared. A web application, its API and its mobile client are commonly scoped together since an attacker does not treat them as separate systems either.
Is every service delivered on the platform?
Every testing engagement is: findings publish to your workspace as they are confirmed, retests are requested in place, and reports generate in the profile you need. There is no separate platform licence. The exceptions are the engagements that do not produce findings of that kind - the cloud configuration review, compliance consulting, phishing simulation and dark web monitoring are delivered as documents, and each of those pages says so.
Not sure what you need?
Prefer writing to talking? A paragraph is enough - what needs testing, and what is driving the date. We will reply with what we would scope and why.