ServicesPEN
We break it first,on paper
Scoped · authorised · retested
We attack the system the way someone else eventually will, then hand you the findings ranked by what each one would actually cost.
Best whenYou are going live, taking payments, or a client has asked for a report.
- Scope
- Signed before testing
- Method
- Manual, not just scans
- Report
- Ranked by real impact
- Retest
- One, included
Four steps
A scanner produces a list. A test produces a route into your system and a number attached to what that route would cost. We do the second one, and only against a system you have authorised us in writing to test.
01
Scope and authorisation
Which hosts, which accounts, which hours, and who to call if something falls over. Signed by someone who owns the system before a single request is sent.
02
Map the surface
Every endpoint, role and integration the application exposes — including the ones nobody remembered were still deployed. That inventory is usually the first finding.
03
Test by hand
OWASP Top 10 as a floor, then the business-logic flaws no tool can see: a price a client can set, an ID a customer can change, a limit an admin route forgot.
04
Report, fix, retest
Findings ranked by what an attacker gets, with the exact request that proves it. Once your fixes are live we run it again, free, and confirm each one in writing.
What lands in your accounts
Testing only ever runs against systems you own or have written permission to test, inside the window we agreed. That is a condition of the engagement, not a disclaimer.
- A written, signed scope and authorisation before any testing starts
- OWASP Top 10 plus the business-logic flaws a scanner cannot see
- Findings ranked by real impact, not by a tool severity score
- One free retest once your fixes are deployed
PricingPriced from the written scope — one figure, agreed before code. No hourly billing, no change-request desk.
Severity means a response
A scanner grades on category. We grade on what an attacker actually gets and what it would cost you, and every grade carries the response that goes with it — so the report is a plan, not a list.
Critical
Money or customer data leaves the system without a login.
You hear from us the same day, before the report is written.
High
A signed-in user reaches another account, or an admin route.
Fixed before the next release ships. We retest that one first.
Medium
Real, but needs a condition an attacker has to arrange.
Scheduled, with the workaround to run until it lands.
Low
Hardening. No route to impact found during the window.
Listed with the fix, for the next time that file is open.
Next step
Tell us what
you need built
Send the idea in whatever shape it is in — a document, a sketch, or two sentences. You get a written scope and a fixed figure back before anything is committed to.