Who we serve

For software companies whose next deal depends on a security review.

Your customers’ procurement teams want a recent penetration test, a SOC 2 report, and answers to two hundred questions. We test the product the way an attacker would, and write the report so it survives a procurement review.

What we usually find

Where multi-tenant products break.

01 Tenant isolation Object IDs that can be swapped in a request to read another customer’s data. Still the most common critical finding we write up.
02 Role and permission drift Features added after the permission model was designed, with checks enforced in the interface but not on the server.
03 API surface nobody listed Mobile, partner and internal endpoints that ship alongside the documented API and never make it into scope documents.
04 Integrations and webhooks Server-side request forgery through URL fields, and webhook endpoints that accept unsigned payloads.
Frameworks this sector answers to

OWASP ASVS 5.0, the OWASP API Security Top 10 and SOC 2 — plus ISO/IEC 27001:2022 for customers in Europe.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Have an enterprise deal waiting on a pen test?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.