Find the holes before your customer's security team does.
A penetration test is a controlled attack on your own website or API. We try to break in the way a real attacker would, then write down exactly what worked and how to fix it.
- Fixed scope and price, quoted in writing before anything is touched
- OWASP coverage, led by a Cisco-certified ethical hacker with a national CTF podium finish
- One free retest once you have fixed what we found
Broken object-level authorization
An authenticated user reads another tenant's records by changing the id on /api/v1/invoices/{id}.
→ Enforce object-level authorization on every route. Retest included.
This is an example of how we write findings, not a real client's result. Client reports are confidential.
We are not a QSA firm — and we'll tell you when you need one.
We produce the penetration-test report and the technical evidence your auditor asks for.
We are not a QSA, an ASV, or a CPA firm.
We do not issue SOC 2 attestations or PCI Reports on Compliance — and we'll tell you plainly the moment you need someone who does.
What we do
Four services: penetration testing, an attack surface baseline, server and cloud hardening, and Wazuh SIEM in your own cloud.
Web & API Penetration Testing
- Black-box + authenticated gray-box
- OWASP Top 10 (2021) + OWASP API Top 10
- CVSS v3.1 scoring, reproduction steps, evidence
- One verification retest included
Attack Surface Baseline
- Exposed services, admin panels, TLS/headers
- SPF/DKIM/DMARC/DNSSEC, dependency CVEs
- Cloud-storage misconfig, secrets in repos
- Report in 5 days — credited toward a pentest
Server & Cloud Hardening
- Linux & cloud hardening to CIS baselines
- Firewalls, NGINX/Apache, MFA/IAM cleanup
- Secrets management, CI/CD scanning
- Cloud VPN / zero-trust access, as code
Wazuh SIEM — in your cloud
- Agents, rules, decoders, dashboards
- Deployed in your own account — you own it
- Produces the log & IDS evidence auditors want
- Not a 24/7 SOC — and we won't pretend to be
Start on your own with the free website check.
The Attack Surface Baseline is the paid, thorough version of something you can start on your own. The free website check reads what your site already exposes to every visitor, and tells you what it found:
- Response headers
- TLS certificate
- A handful of commonly guessed paths
It is a passive read, not a penetration test — it will not find the flaws specific to your application, and it does not pretend to.
A vulnerability scan is not a penetration test.
A vulnerability scan is a tool run. It fires known signatures at your site and prints what matched. It is fast, it is cheap, and it is worth doing — but it can only find bugs somebody has already written a signature for.
A penetration test is an engineer using those same tools and then reasoning about your application. A scanner has no idea that customer number 4,412 should not be able to open invoice number 3,118. It does not know what a booking is, or which of your pages is supposed to require a login. Every serious finding in our reports comes from someone understanding your business rules and then deliberately breaking them.
We sell both, and they are named above: the Attack Surface Baseline is the scan, read by a human rather than emailed to you raw. The penetration test is the reasoning. If someone is asking you for a pentest, scanner output on its own will not satisfy them.
How an engagement runs.
Five stages, agreed in writing before anything is touched. Nothing is tested that isn't on the list.
Penetration-test engagement stages and deliverables
Scope & rules of engagement
Targets, test window and out-of-scope systems agreed in writing. NDA signed on every engagement.
You receive → Fixed scope, fixed price, fixed dates
Attack surface baseline
Exposed services, admin panels, TLS/headers, SPF/DKIM/DMARC/DNSSEC, dependency CVEs, cloud-storage misconfig, secrets in repos.
You receive → Baseline report in 5 days
Testing
Black-box first, then authenticated gray-box against OWASP Top 10 (2021) and the OWASP API Top 10 — on staging, IP-whitelisted. No production access needed.
You receive → Findings with working reproduction steps
Report
Each finding scored with CVSS v3.1, with evidence and fix-first remediation your developers can act on, plus a summary letter for your auditor.
You receive → CVSS-scored report + summary letter
Retest
Once you have shipped the fixes we test the same findings again and mark what is closed.
You receive → One verification retest, included
Tested on staging, not production.
Testing runs against staging, IP-whitelisted, under agreed rules of engagement. We do not need production access, and we don't ask for it.
Scored the way your auditor reads it.
Every finding carries a CVSS v3.1 score, so your developers and your auditor rank the same list the same way. The bands below are the published CVSS qualitative scale — not a rating we invented.
| Severity | CVSS v3.1 |
|---|---|
| Critical | 9.0 – 10.0 |
| High | 7.0 – 8.9 |
| Medium | 4.0 – 6.9 |
| Low | 0.1 – 3.9 |
| None | 0.0 |
Fixed scope, quoted in writing.
Every engagement is scoped and quoted in writing before work begins.
Attack Surface Baseline
A fast 5-day external review and report; credited toward a full pentest booked within 30 days.
Penetration Test
A defined web & API test with a fixed scope, price and dates — the report your auditor accepts, plus one retest.
Hardening / VPN / SIEM
Scoped to your infrastructure, day-rate or fixed-scope, quoted after a short call.
The same engineers build websites hardened to this standard, and host and harden ERPNext for businesses whose financial data sits inside it.
For a walk-through of the kind of thing we find, read what a penetration test actually finds on a small business website.
If an audit is what brought you here, SOC 2 never actually names a penetration test — yet nearly every auditor asks for one. what a soc 2 auditor actually wants from your penetration test sets out what the report has to contain, and what scope and retest mean in practice.
Common questions
What is the difference between a vulnerability scan and a penetration test?
A scan is a tool run: it fires known signatures at your site and prints what matched. It is fast, it is worth doing, and it can only find bugs somebody has already written a signature for. A penetration test is an engineer using those same tools and then reasoning about your application — a scanner has no idea that customer 4,412 should not be able to open invoice 3,118. We sell both: the Attack Surface Baseline is the scan, read by a human; the penetration test is the reasoning.
Will you sign an NDA?
Yes — every engagement.
Do you need production access?
No — we test staging, IP-whitelisted, with agreed rules of engagement.
Do you issue SOC 2 or PCI compliance?
No. We're not a QSA, ASV or CPA firm. We produce the pentest report and technical evidence your auditor accepts, and we'll tell you when you need a licensed firm.
What's the deliverable?
A CVSS-scored report with reproduction steps and fix-first remediation, plus a summary letter, and one free retest.
Book a 20-minute scoping call.
No obligation — we'll tell you what's worth testing and what a fixed quote looks like.