Scope
The scope statement is signed before work starts: assets included, assets excluded and the rules of engagement. The statement also records test credentials, the testing window and the notification channel.
SERVICE · PENETRATION TESTING
Manual, verified exploitation across web applications, REST and GraphQL APIs, internal networks and mobile. Report with a working PoC and CVSS.
The scope statement is signed before work starts: assets included, assets excluded and the rules of engagement. The statement also records test credentials, the testing window and the notification channel.
An inventory of the published surface: domains, endpoints, versions and roles. Exposed assets that are missing from your inventory are covered as well.
The team chains each flaw until the impact is proven, then stops testing before any damage is done. Exploitation is manual and verified: scanner output is not a finding.
The same team walks your team through the report in a review session. The engagement closes with a retest of every fix.
The ones named in the scope statement: session-based web applications, REST and GraphQL APIs, internal networks and mobile. Anything not listed there is out of scope, and any extension is agreed in writing before it is tested.
The technical report, with reproduction steps and a working proof of concept for every exploitable finding. The NDA covers the report and everything the team sees during the audit.
Yes. The team retests every fix, and a signed closure report records the final status of each finding.
Tell us which assets you want tested. We reply within 24 hours.