Skip to content

SERVICE · PENETRATION TESTING

Web, API, network and mobile pentesting with manual, verified exploitation

Manual, verified exploitation across web applications, REST and GraphQL APIs, internal networks and mobile. Report with a working PoC and CVSS.

  • Web
  • API
  • Internal network
  • Mobile

Technical scope

  • Session-based web applications: portals, dashboards and SPAs
  • REST and GraphQL APIs, authenticated and unauthenticated
  • Internal networks: segmentation, exposed services and lateral movement
  • iOS and Android applications, client and backend
  • Manual exploitation of every vulnerability until impact is proven
  • Severity justified with its CVSS vector, finding by finding

Deliverables

  • Technical report with reproduction steps
  • Working proof of concept for every exploitable finding
  • CVSS scoring with its vector
  • Remediation plan ranked by impact
  • Retest of every fix, included in the engagement

Audit phases

PHASE 01

Scope

The scope statement is signed before work starts: assets included, assets excluded and the rules of engagement. The statement also records test credentials, the testing window and the notification channel.

Scope statement
PHASE 02

Reconnaissance

An inventory of the published surface: domains, endpoints, versions and roles. Exposed assets that are missing from your inventory are covered as well.

Surface map
PHASE 03

Manual exploitation

The team chains each flaw until the impact is proven, then stops testing before any damage is done. Exploitation is manual and verified: scanner output is not a finding.

Reproducible PoC
PHASE 04

Report and retest

The same team walks your team through the report in a review session. The engagement closes with a retest of every fix.

Report and closure

Frequently asked questions

Which surfaces are in scope?

The ones named in the scope statement: session-based web applications, REST and GraphQL APIs, internal networks and mobile. Anything not listed there is out of scope, and any extension is agreed in writing before it is tested.

What is delivered at the end?

The technical report, with reproduction steps and a working proof of concept for every exploitable finding. The NDA covers the report and everything the team sees during the audit.

Is the retest included?

Yes. The team retests every fix, and a signed closure report records the final status of each finding.

Published findings of this kind

Request the scope in writing

Tell us which assets you want tested. We reply within 24 hours.

Request an auditCall