Skip to main content
davque

Analysis on our own hardware – no code sent to cloud AI

Penetration testing for software companies.

We mainly do red teaming. Our penetration-testing models scan your codebase for known CVEs, then we run our own pentest on top, as a whitebox or blackbox run. A person verifies every finding.

Non-binding, 30 minutes. No test without written authorization.

sample_report_saas.pdf

Findings · excerpt

4 / 27

  • DVQ-2026-014

    IDOR in /api/v2/invoices/{id}

    8.1
  • DVQ-2026-015

    Missing rate limits on login

    5.3
  • DVQ-2026-016

    API token in git history

    7.5
  • DVQ-2026-017

    Reflected XSS in search field

    3.1
26 verified1 discarded as false positiveCVSS v4.0
  • Own hardware

    Models run on our own servers in Germany

  • Verification

    Every finding is verified by a person

  • Legal framework

    Only with written authorization

  • Test modes

    Whitebox and blackbox

What we do

Known CVEs first, then our own pentest

A person verifies every finding.

01

Known-CVE scan

We scan your codebase and its dependencies for known CVEs and document every CVE we tested, not just the hits.

02

Our own pentest on top

Our penetration-testing models test what no CVE list contains: business logic, permission models, attack chains.

03

Verified by a person

An analyst reproduces every candidate and discards what does not hold up. The report contains verified findings only.

Test modes

Whitebox and blackbox

Both modes use our penetration-testing models, and a person verifies every finding. They differ in what we know about your system at the start.

Whitebox

With source code access

You give us the source code and, if possible, architecture notes and a test environment.

What we do

  • Scan the codebase and its dependencies for known CVEs, in an isolated offline environment
  • Run our own penetration testing on top, for what no CVE list contains
  • Attack the running application using what the code shows
  • Trace findings to file and line

Blackbox

Without insider knowledge

We get the target and the scope, nothing else. We work like an external attacker, without source code or architecture documents.

What we do

  • Map the attack surface from the outside
  • Probe it with our penetration-testing models, over the internet from our own infrastructure
  • Exploit manually and chain findings
  • Show what an attacker can actually reach

Not sure which fits? We recommend a mode during scoping. The two can be combined. Details on the modes.

Process

How it works

See the process
  1. 01

    Scope

    Intro call, whitebox or blackbox, written authorization.

  2. 02

    Scan and test

    CVE scan, then our own pentest on top.

  3. 03

    Verify

    Every finding is reproduced by an analyst.

  4. 04

    Report and retest

    Report, debrief, retest after the fix.

The report

What the report contains

Findings classified by CWE, the full list of CVEs we tested, our own pentesting methodologies and a record of what we did.

See the report

Source code you hand over is analysed in an isolated, offline environment on our own hardware. It is never sent to cloud AI providers.

Security and trust

Book an intro call

30 minutes, non-binding. We clarify scope, test mode and price.

  • No test without written authorization and a defined scope.
  • Source code and test data never go to cloud AI providers.
  • Every finding is verified by a person before delivery.