ServicesPEN

We break it first,on paper

Scoped · authorised · retested

We attack the system the way someone else eventually will, then hand you the findings ranked by what each one would actually cost.

Best whenYou are going live, taking payments, or a client has asked for a report.

Scope
Signed before testing
Method
Manual, not just scans
Report
Ranked by real impact
Retest
One, included
  • React
  • Next.js
  • Vue.js
  • TypeScript
  • Node.js
  • Python
  • Astro
  • Bun
  • React Native
  • Expo
  • GraphQL
  • REST
  • Playwright
  • Vitest
  • Figma
  • Burp Suite

01How it runs

Four steps

A scanner produces a list. A test produces a route into your system and a number attached to what that route would cost. We do the second one, and only against a system you have authorised us in writing to test.

  1. 01

    Scope and authorisation

    Which hosts, which accounts, which hours, and who to call if something falls over. Signed by someone who owns the system before a single request is sent.

  2. 02

    Map the surface

    Every endpoint, role and integration the application exposes — including the ones nobody remembered were still deployed. That inventory is usually the first finding.

  3. 03

    Test by hand

    OWASP Top 10 as a floor, then the business-logic flaws no tool can see: a price a client can set, an ID a customer can change, a limit an admin route forgot.

  4. 04

    Report, fix, retest

    Findings ranked by what an attacker gets, with the exact request that proves it. Once your fixes are live we run it again, free, and confirm each one in writing.

02In scope

What lands in your accounts

Testing only ever runs against systems you own or have written permission to test, inside the window we agreed. That is a condition of the engagement, not a disclaimer.

  • A written, signed scope and authorisation before any testing starts
  • OWASP Top 10 plus the business-logic flaws a scanner cannot see
  • Findings ranked by real impact, not by a tool severity score
  • One free retest once your fixes are deployed

PricingPriced from the written scope — one figure, agreed before code. No hourly billing, no change-request desk.

03How findings rank

Severity means a response

A scanner grades on category. We grade on what an attacker actually gets and what it would cost you, and every grade carries the response that goes with it — so the report is a plan, not a list.

  1. Critical

    Money or customer data leaves the system without a login.

    You hear from us the same day, before the report is written.

  2. High

    A signed-in user reaches another account, or an admin route.

    Fixed before the next release ships. We retest that one first.

  3. Medium

    Real, but needs a condition an attacker has to arrange.

    Scheduled, with the workaround to run until it lands.

  4. Low

    Hardening. No route to impact found during the window.

    Listed with the fix, for the next time that file is open.

Next step

Tell us what
you need built

Send the idea in whatever shape it is in — a document, a sketch, or two sentences. You get a written scope and a fixed figure back before anything is committed to.