Cybersecurity

Penetration testing (VAPT) with a report your auditor can use

Hands-on vulnerability assessment and penetration testing for web apps, APIs, mobile apps, networks and cloud, ending with clear findings, fixes and a retest.

How it works
1Scope2Test3Report4Fix5Retest

What we test

Web applications and APIs

Testing against the OWASP Top 10 and ASVS: authentication, access control, injection and business logic flaws.

Network and infrastructure

External and internal testing of servers, firewalls, VPNs and Active Directory.

Mobile applications

Testing of iOS and Android apps together with the APIs behind them.

Cloud environments

Configuration and exposure testing for AWS, Azure and Google Cloud.

AI applications

Prompt injection, data leakage and agent permission testing for LLM-based systems.

See AI solutions

Red team and adversary simulation

Goal-based attack simulation that tests people, process and technology together.

How a test runs

  1. Step 1

    Scoping and rules of engagement

    We agree what is in scope, what is off limits and when testing happens.

  2. Step 2

    Testing

    Manual testing supported by tools, following recognized methodology.

  3. Step 3

    Reporting

    A report written for both management and developers.

  4. Step 4

    Remediation support

    We answer your developers' questions and explain each fix.

  5. Step 5

    Retest

    We verify the serious findings are closed and update the report.

The report

The report is the deliverable most clients actually need.

What is in it

  • Executive summary for management
  • Scope, method and limits of the test
  • Findings ranked by severity, with evidence
  • Step-by-step remediation guidance
  • Retest results confirming fixes

Where it is used

  • PCI DSS, which requires regular penetration testing
  • SOC 2 and ISO 27001 audits, where auditors commonly ask for recent test reports
  • HIPAA security risk analysis evidence
  • Customer security questionnaires and procurement reviews

A penetration test report is evidence for your auditor. It supports compliance work but does not by itself make a system compliant or certified. Testing is done by our security engineers, separate from the developers who wrote the code.

Standards and references

OWASP Top 10OWASP ASVSNIST SP 800-115CVSS scoring

Common questions

Something missing? Ask on the consultation call and we will answer it straight.

How long does a test take?

Most web application tests take one to three weeks, depending on size and complexity. We confirm a schedule when we agree scope.

Will testing disrupt our live systems?

We agree rules of engagement first, prefer test environments where possible and coordinate timing for anything sensitive.

Do you retest after we fix the issues?

Yes. A retest of the serious findings is part of the service, and the final report shows what was fixed.

Related services

GRC and compliance

SOC 2, ISO 27001, HIPAA and PCI DSS readiness.

See GRC and compliance

Custom software development

Web, mobile and API software with security built in.

See custom software development

SOC monitoring

Level 1 monitoring and triage on the SIEM you already run.

See SOC monitoring

Tell us what you are building or protecting

Book a free 30-minute consultation. An engineer will reply within one business day.

WhatsApp