Skip to main content
davque

Services

What we offer

We do penetration testing, mainly red teaming: we get a target and work towards it the way a real attacker would.

Red teaming

Red teaming

A defined attack goal instead of a checklist. We test the whole path to it.

External attack surface

Forgotten subdomains, exposed systems, leaked credentials.

Identities and access

Privilege escalation, CI/CD and cloud permissions.

Applications and APIs

Authentication, authorization, injection, business logic.

Source code

Known CVEs, secrets and insecure data flows (whitebox).

Processes

Approval and release steps that can be bypassed.

Approach

How we test

01

Known-CVE scan

We scan your codebase and its dependencies for known CVEs and document every CVE we tested.

02

Our own pentest on top

Our penetration-testing models test what no CVE list contains.

03

Verification

A person reproduces every finding before it goes into the report.

Test modes

Whitebox and blackbox

Both modes use our penetration-testing models, and a person verifies every finding. They differ in what we know about your system at the start.

Whitebox

With source code access

You give us the source code and, if possible, architecture notes and a test environment.

What we do

  • Scan the codebase and its dependencies for known CVEs, in an isolated offline environment
  • Run our own penetration testing on top, for what no CVE list contains
  • Attack the running application using what the code shows
  • Trace findings to file and line
We need
Read access to the repository (handed over to our offline environment), a test environment, NDA and written authorization.
Best for
Release checks, audit evidence and security-critical products. Deepest coverage.

Blackbox

Without insider knowledge

We get the target and the scope, nothing else. We work like an external attacker, without source code or architecture documents.

What we do

  • Map the attack surface from the outside
  • Probe it with our penetration-testing models, over the internet from our own infrastructure
  • Exploit manually and chain findings
  • Show what an attacker can actually reach
We need
A defined scope (domains, IP ranges, APIs) and written authorization. Test accounts, if any, are agreed in scoping.
Best for
An external view of your exposure, or when the code cannot be shared.

Not sure which fits? We recommend a mode during scoping. The two can be combined.

Book an intro call

30 minutes, non-binding. We clarify scope, test mode and price.

  • No test without written authorization and a defined scope.
  • Source code and test data never go to cloud AI providers.
  • Every finding is verified by a person before delivery.