- Home
- Services
Services
Fifteen services in four groups. Most clients start with a penetration test and add the rest as their program grows. If you're not sure which you need, tell us what's driving the work and we'll recommend a scope.
Penetration testing
Manual testing by certified testers, aimed at the systems attackers reach first.
- Web application penetration testing Authenticated, manual testing of your web apps, from the login page to business logic.
- API penetration testing REST, GraphQL, gRPC, and WebSocket APIs tested for authorization flaws and data exposure.
- Mobile application penetration testing iOS and Android apps tested on-device, together with the APIs behind them.
- Network penetration testing External perimeter, internal network, Active Directory, and wireless testing.
- Cloud penetration testing and configuration review AWS, Azure, Google Cloud, and Kubernetes tested for misconfiguration and privilege escalation.
- AI and LLM security testing Prompt injection, data leakage, and agent abuse testing for AI features and LLM applications.
Adversary simulation
Test your people, processes, and detection, not just your software.
Code and vulnerability management
Catch flaws before release and keep known vulnerabilities under control.
- Secure code review Manual review of your source code, backed by static analysis, to find flaws before they ship.
- Vulnerability scanning Authenticated internal, external, and web scanning with false positives removed.
- Vulnerability management A managed program that tracks every vulnerability from discovery to verified fix.
- Continuous testing and attack surface monitoring Ongoing discovery of what you expose online, with testers checking what matters.
Assurance and advisory
Audit-ready testing, design reviews, and hands-on training.
- Compliance penetration testing Pen tests scoped and reported for SOC 2, HIPAA, ISO 27001, and customer security reviews.
- Threat modeling and architecture review Design and architecture reviews that find security flaws before they're built or exploited.
- Security training Hands-on training for developers and security teams, taught by working testers.
Tell us what you need tested.
Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.