Test it, audit it, or keep it tested.

Nine services in three groups: hands-on testing that finds what an attacker would, independent assessments against the frameworks you answer to, and ongoing assurance for teams that ship every week. No bronze, silver and gold packages — the scope is the scope, and the price follows it.

Test

Offensive testing

Manual, authorised attacks on what you ship. Scoped up front, priced up front, retest included.

01

Web application penetration testing

A person working through your application the way an attacker would — every role, every workflow, every place one user might reach another user’s data. We follow the OWASP Web Security Testing Guide and measure against OWASP ASVS 5.0, so coverage is documented rather than assumed.

  • +OWASP Top 10:2025 and ASVS 5.0 coverage
  • +Business-logic and authorisation testing
  • +Retest of critical and high findings
02

API security testing

REST, GraphQL and the mobile back ends nobody documented. We test against the OWASP API Security Top 10 (2023), with particular attention to object-level and property-level authorisation — the flaws that leak whole databases one ID at a time.

  • +OpenAPI, Postman or discovery-led
  • +BOLA, BOPLA and BFLA testing
  • +Rate limiting and resource abuse
03

Cloud & external attack surface review

What the internet can see of you: forgotten subdomains, exposed storage, open admin panels, and the cloud configuration behind your application. Benchmarked against the CIS Foundations Benchmarks for AWS, Azure and Google Cloud.

  • +External asset discovery
  • +Cloud configuration review
  • +Identity and key exposure
Audit

Independent assessment

Where you stand against a recognised framework, written so leadership can read it and engineering can act on it.

04

Security audit against a framework

A structured assessment of your organisation against NIST CSF 2.0, the CIS Controls v8.1 or ISO/IEC 27001:2022 — interviews, evidence review and technical spot-checks. You get a maturity score per area, a prioritised roadmap, and a one-page summary for the board.

  • +NIST CSF 2.0 profile and tiers
  • +CIS Controls v8.1 IG1–IG3
  • +Prioritised remediation roadmap
05

Compliance readiness

Getting ready for the assessment someone else will perform: SOC 2 (Type I or Type II), ISO/IEC 27001:2022 certification, or PCI DSS v4.0.1. Gap analysis, policies that match how you actually work, evidence collection, and a mock audit before the real one.

  • +SOC 2 Trust Services Criteria
  • +ISO 27001 ISMS and Statement of Applicability
  • +PCI DSS v4.0.1 incl. 6.4.3 and 11.6.1
06

Secure code & architecture review

Reading the code and the design, not just poking the running system. Authentication, session handling, cryptography, data flows and infrastructure-as-code, reviewed against ASVS 5.0 with findings tied to the exact file and line.

  • +Manual review of high-risk paths
  • +Threat modelling workshop
  • +Infrastructure-as-code review
Run

Ongoing assurance

Security is not a once-a-year event when you deploy every week.

07

Continuous testing

Testing on your release cadence instead of the calendar: each significant release, or a fixed quarterly cycle, with a rolling report that is never more than a quarter old when a customer asks for it.

  • +Release-triggered or quarterly testing
  • +Rolling report and summary letter
  • +Priority retesting
08

Fractional security lead

A named senior security lead for a set number of hours a month. Customer questionnaires, the risk register, vendor reviews, audit preparation and a standing seat in engineering planning — without a full-time hire.

  • +Security questionnaires answered
  • +Risk register and policy ownership
  • +Audit and board reporting
09

Incident readiness & tabletop exercises

Rehearsing the bad day before it happens. We write or review your incident response plan, then run a realistic scenario with leadership and engineering — ransomware, a leaked key, a compromised vendor — and report what broke.

  • +Incident response plan review
  • +Scenario-based tabletop exercise
  • +After-action report and fixes
How we work together

Three ways to engage.

Fixed scope

Engagement

One defined test or audit, priced up front with a written scope and rules of engagement. Most first engagements run this way — you know the number before anything starts.

Included

Retest & summary letter

After you fix, we verify every critical and high finding within 90 days and issue a summary letter you can share with customers and auditors without exposing the detail.

Continuous

Retainer

A standing arrangement for continuous testing, a fractional security lead, or both — for teams shipping often enough that separate engagements stop making sense.

Questions

The ones we get asked most.

What does a penetration test cost?
It depends on scope — number of roles, endpoints, environments and the depth of verification. The estimator on this site gives a range in about a minute, and a lead assessor reviews every estimate before a written proposal goes out.
How long does it take?
Most web application tests are one to three weeks of testing, with a draft report within five business days of the last test day. Audits run three to six weeks; readiness programmes two to four months.
What does the process look like?
Scope, test, fix, verify. We agree scope and rules of engagement in writing, test with daily check-ins and immediate escalation of anything critical, deliver the report with a walkthrough, then retest your fixes.
Do you need access to our source code?
Not for a standard test. For grey-box testing we need accounts for each role and any API documentation. Source access lets us go deeper and is required for a secure code review.
Do you test in production?
Only if you want us to, within agreed windows and rate limits. A production-like staging environment is preferred. Destructive and denial-of-service testing never happens without explicit written approval.
Can we share the report with customers?
Share the summary letter. It confirms scope, dates, methodology and the status of findings at retest, without handing an attacker a map. The full report stays with your team and auditors.
Can you issue our SOC 2 report or ISO 27001 certificate?
No. SOC 2 reports are issued by licensed CPA firms and ISO 27001 certificates by accredited certification bodies. We get you ready for both, and work alongside your chosen auditor.
Which framework should we start with?
The one your customers or regulators ask for. If nobody has asked yet, the CIS Controls v8.1 Implementation Group 1 is the best practical starting line, and NIST CSF 2.0 is the best way to explain your position to leadership.
Do you use automated scanners?
Yes, as a starting point for coverage. They never replace manual testing, and a scanner export is never the deliverable. Most of the serious findings in our reports are things no scanner flags.
Are you independent of the tools you recommend?
Yes. We do not resell security products or take referral fees, so a recommendation to buy something is never how we get paid.
How do we start?
Run the estimator for a range, or send a note and we will set up a scoping call. Either reaches a tester, not a sales team.

Get a scoping range before you get on a call.

The estimator asks what you need tested or audited, then gives you a real range — not a form that promises someone will be in touch.