Find what an attacker would find first
Manual testing against your network, applications and APIs. Exploitable weaknesses proven and ranked, with a retest once you have fixed them.
The challenge
An automated scan tells you what might be wrong. It cannot tell you what is reachable, chainable or exploitable in your environment. Clients and insurers increasingly ask for evidence, and a scan report does not satisfy them.
Scope — included and not included
Included
- External network perimeter
- Internal network, assumed breach
- Web applications, OWASP
- REST and GraphQL APIs
- Authenticated and unauthenticated testing
- One retest within 30 days
Not included
- Social engineering, sold separately
- Physical intrusion
- Denial of service testing
- Source code review
- Remediation work itself
- Third party systems without written consent
How it works
01
Scoping
Targets, rules of engagement, testing windows, emergency contacts.
02
Testing
Manual, PTES and OWASP methodology. Critical findings reported same day.
03
Reporting
Technical plus executive report, presented in a live walkthrough.
04
Retest
Fixed findings verified and the report reissued — included.
What you receive
- →Technical report, 30 to 50 pages, reproduction steps for every finding
- →Executive summary, two pages, no jargon
- →Prioritisation matrix by exploitability and business impact
- →Retest report
- →Attestation letter, shareable with clients and insurers
What we need from you
- ·A named technical contact
- ·Target list and IP ranges
- ·Test credentials if authenticated
- ·Signed authorisation
- ·Roughly four hours of your team's time
Timeline and engagement
Scoping call to report: 3 to 4 weeks. Testing window 1 to 3 weeks. Fixed scope, fixed price, retest included.
Standards, methods and tooling
PTESOWASP WSTGMITRE ATT&CKCVSS 4.0eWPTXCRTPPJPTPortal hosted in Canada
Frequently asked questions