External & internal penetration testing
What an attacker reaches from the internet, and what they reach once they already have a foothold inside the network. Both answers matter, and they are rarely the same.
Offensive security
Independent penetration testing for web applications, APIs, internal networks and AI systems. Every finding is verified by hand, written up with the steps to reproduce it, and retested once you have fixed it.
Services
Engagements are sized around your estate and your risk, not sold as a fixed package. Most clients start with one area and widen from there.
What an attacker reaches from the internet, and what they reach once they already have a foothold inside the network. Both answers matter, and they are rarely the same.
Authenticated and unauthenticated. Beyond the OWASP Top 10 into the things scanners cannot reach: business logic, access control between roles and tenants, and session handling.
REST and GraphQL. Authorisation flaws, mass assignment, rate limiting, and the undocumented endpoints that never made it into the spec but are still answering requests.
Prompt injection, data leakage through context and retrieval, tool and agent abuse — and the blast radius when a model is wired to systems that can actually change something.
How we work
You know the scope, the timing and the rules of engagement before any traffic is sent.
We agree targets, depth, testing window and rules of engagement, and put them in writing. Out-of-scope stays out of scope. If we find something that suggests the scope is wrong, we come back and ask rather than widening it ourselves.
Manual testing led by a person, with tooling where tooling genuinely helps. Anything that looks critical is reported the same day rather than held back for the final document — you should not learn about a live exposure three weeks late.
Every finding with evidence, reproduction steps, a severity rating and a specific remediation — not “implement input validation”, but what to change and where. Plus a summary written for people who will not read the technical section.
Once your team has worked through the findings, we verify the fixes and reissue the report. A finding is only closed when we have confirmed it. This is included, not a separate engagement.
What you get
The test is only worth what the write-up makes possible. Findings are verified before they reach you — we do not pass on scanner output and leave you to work out which half is real.
FAQ
It depends on scope. A single web application is typically a matter of days; a full internal network assessment takes longer. We give you a duration and a price with the scope document, before you commit — not an hourly meter.
Tell us what you need tested and we will come back with availability and a scope. Urgent work — a pending release, a compliance deadline, an incident — is worth saying up front, because it changes how we sequence things.
The methodology does not change much between sectors; what changes is the threat model and the compliance context. If you have specific regulatory requirements, tell us during scoping so the report is structured to satisfy them.
We work under NDA as standard. Engagement data is kept encrypted, shared only through channels you agree to, and destroyed on an agreed schedule after delivery. We do not retain client data to build marketing material from it.
Testing is conducted to avoid disruption, and anything genuinely destructive is only performed with explicit written approval and an agreed window. If you would rather we tested a staging environment, that is a legitimate choice — we will tell you what it means for coverage.
An executive summary, then one entry per finding with evidence, reproduction steps, severity and remediation — the format shown at the top of this page. We are happy to send a redacted sample before you commit to anything.
Get in touch
A short description of the systems and what you are worried about is enough to start. We will come back with scope, timing and a price before anything is committed.
Request a scoping call