Penetration testing (VAPT) with a report your auditor can use
Hands-on vulnerability assessment and penetration testing for web apps, APIs, mobile apps, networks and cloud, ending with clear findings, fixes and a retest.
What we test
Web applications and APIs
Testing against the OWASP Top 10 and ASVS: authentication, access control, injection and business logic flaws.
Network and infrastructure
External and internal testing of servers, firewalls, VPNs and Active Directory.
Mobile applications
Testing of iOS and Android apps together with the APIs behind them.
Cloud environments
Configuration and exposure testing for AWS, Azure and Google Cloud.
AI applications
Prompt injection, data leakage and agent permission testing for LLM-based systems.
See AI solutionsRed team and adversary simulation
Goal-based attack simulation that tests people, process and technology together.
How a test runs
- Step 1
Scoping and rules of engagement
We agree what is in scope, what is off limits and when testing happens.
- Step 2
Testing
Manual testing supported by tools, following recognized methodology.
- Step 3
Reporting
A report written for both management and developers.
- Step 4
Remediation support
We answer your developers' questions and explain each fix.
- Step 5
Retest
We verify the serious findings are closed and update the report.
The report
The report is the deliverable most clients actually need.
What is in it
- Executive summary for management
- Scope, method and limits of the test
- Findings ranked by severity, with evidence
- Step-by-step remediation guidance
- Retest results confirming fixes
Where it is used
- PCI DSS, which requires regular penetration testing
- SOC 2 and ISO 27001 audits, where auditors commonly ask for recent test reports
- HIPAA security risk analysis evidence
- Customer security questionnaires and procurement reviews
A penetration test report is evidence for your auditor. It supports compliance work but does not by itself make a system compliant or certified. Testing is done by our security engineers, separate from the developers who wrote the code.
Standards and references
Common questions
Something missing? Ask on the consultation call and we will answer it straight.
How long does a test take?
Most web application tests take one to three weeks, depending on size and complexity. We confirm a schedule when we agree scope.
Will testing disrupt our live systems?
We agree rules of engagement first, prefer test environments where possible and coordinate timing for anything sensitive.
Do you retest after we fix the issues?
Yes. A retest of the serious findings is part of the service, and the final report shows what was fixed.
Related services
Custom software development
Web, mobile and API software with security built in.
See custom software developmentTell us what you are building or protecting
Book a free 30-minute consultation. An engineer will reply within one business day.