Services
What we offer
We do penetration testing, mainly red teaming: we get a target and work towards it the way a real attacker would.
Red teaming
Red teaming
A defined attack goal instead of a checklist. We test the whole path to it.
External attack surface
Forgotten subdomains, exposed systems, leaked credentials.
Identities and access
Privilege escalation, CI/CD and cloud permissions.
Applications and APIs
Authentication, authorization, injection, business logic.
Source code
Known CVEs, secrets and insecure data flows (whitebox).
Processes
Approval and release steps that can be bypassed.
Approach
How we test
Known-CVE scan
We scan your codebase and its dependencies for known CVEs and document every CVE we tested.
Our own pentest on top
Our penetration-testing models test what no CVE list contains.
Verification
A person reproduces every finding before it goes into the report.
Test modes
Whitebox and blackbox
Both modes use our penetration-testing models, and a person verifies every finding. They differ in what we know about your system at the start.
Whitebox
With source code access
You give us the source code and, if possible, architecture notes and a test environment.
What we do
- Scan the codebase and its dependencies for known CVEs, in an isolated offline environment
- Run our own penetration testing on top, for what no CVE list contains
- Attack the running application using what the code shows
- Trace findings to file and line
- We need
- Read access to the repository (handed over to our offline environment), a test environment, NDA and written authorization.
- Best for
- Release checks, audit evidence and security-critical products. Deepest coverage.
Blackbox
Without insider knowledge
We get the target and the scope, nothing else. We work like an external attacker, without source code or architecture documents.
What we do
- Map the attack surface from the outside
- Probe it with our penetration-testing models, over the internet from our own infrastructure
- Exploit manually and chain findings
- Show what an attacker can actually reach
- We need
- A defined scope (domains, IP ranges, APIs) and written authorization. Test accounts, if any, are agreed in scoping.
- Best for
- An external view of your exposure, or when the code cannot be shared.
Not sure which fits? We recommend a mode during scoping. The two can be combined.
Book an intro call
30 minutes, non-binding. We clarify scope, test mode and price.
- No test without written authorization and a defined scope.
- Source code and test data never go to cloud AI providers.
- Every finding is verified by a person before delivery.