Analysis on our own hardware – no code sent to cloud AI
Penetration testing for software companies.
We mainly do red teaming. Our penetration-testing models scan your codebase for known CVEs, then we run our own pentest on top, as a whitebox or blackbox run. A person verifies every finding.
Non-binding, 30 minutes. No test without written authorization.
Findings · excerpt
4 / 27
- High8.1
DVQ-2026-014
IDOR in /api/v2/invoices/{id}
- Medium5.3
DVQ-2026-015
Missing rate limits on login
- High7.5
DVQ-2026-016
API token in git history
- Low3.1
DVQ-2026-017
Reflected XSS in search field
Own hardware
Models run on our own servers in Germany
Verification
Every finding is verified by a person
Legal framework
Only with written authorization
Test modes
Whitebox and blackbox
What we do
Known CVEs first, then our own pentest
A person verifies every finding.
Known-CVE scan
We scan your codebase and its dependencies for known CVEs and document every CVE we tested, not just the hits.
Our own pentest on top
Our penetration-testing models test what no CVE list contains: business logic, permission models, attack chains.
Verified by a person
An analyst reproduces every candidate and discards what does not hold up. The report contains verified findings only.
Test modes
Whitebox and blackbox
Both modes use our penetration-testing models, and a person verifies every finding. They differ in what we know about your system at the start.
Whitebox
With source code access
You give us the source code and, if possible, architecture notes and a test environment.
What we do
- Scan the codebase and its dependencies for known CVEs, in an isolated offline environment
- Run our own penetration testing on top, for what no CVE list contains
- Attack the running application using what the code shows
- Trace findings to file and line
Blackbox
Without insider knowledge
We get the target and the scope, nothing else. We work like an external attacker, without source code or architecture documents.
What we do
- Map the attack surface from the outside
- Probe it with our penetration-testing models, over the internet from our own infrastructure
- Exploit manually and chain findings
- Show what an attacker can actually reach
Not sure which fits? We recommend a mode during scoping. The two can be combined. Details on the modes.
Process
How it works
- 01
Scope
Intro call, whitebox or blackbox, written authorization.
- 02
Scan and test
CVE scan, then our own pentest on top.
- 03
Verify
Every finding is reproduced by an analyst.
- 04
Report and retest
Report, debrief, retest after the fix.
The report
What the report contains
Findings classified by CWE, the full list of CVEs we tested, our own pentesting methodologies and a record of what we did.
See the reportSource code you hand over is analysed in an isolated, offline environment on our own hardware. It is never sent to cloud AI providers.
Security and trustBook an intro call
30 minutes, non-binding. We clarify scope, test mode and price.
- No test without written authorization and a defined scope.
- Source code and test data never go to cloud AI providers.
- Every finding is verified by a person before delivery.