Offensive security

Find out what an attacker would find — before they do.

Independent penetration testing for web applications, APIs, internal networks and AI systems. Every finding is verified by hand, written up with the steps to reproduce it, and retested once you have fixed it.

Services

Testing scoped to what you actually run

Engagements are sized around your estate and your risk, not sold as a fixed package. Most clients start with one area and widen from there.

01

External & internal penetration testing

What an attacker reaches from the internet, and what they reach once they already have a foothold inside the network. Both answers matter, and they are rarely the same.

02

Web application testing

Authenticated and unauthenticated. Beyond the OWASP Top 10 into the things scanners cannot reach: business logic, access control between roles and tenants, and session handling.

03

API security testing

REST and GraphQL. Authorisation flaws, mass assignment, rate limiting, and the undocumented endpoints that never made it into the spec but are still answering requests.

04

AI & LLM penetration testing

Prompt injection, data leakage through context and retrieval, tool and agent abuse — and the blast radius when a model is wired to systems that can actually change something.

How we work

Four stages, agreed in writing

You know the scope, the timing and the rules of engagement before any traffic is sent.

  1. Scope

    We agree targets, depth, testing window and rules of engagement, and put them in writing. Out-of-scope stays out of scope. If we find something that suggests the scope is wrong, we come back and ask rather than widening it ourselves.

  2. Test

    Manual testing led by a person, with tooling where tooling genuinely helps. Anything that looks critical is reported the same day rather than held back for the final document — you should not learn about a live exposure three weeks late.

  3. Report

    Every finding with evidence, reproduction steps, a severity rating and a specific remediation — not “implement input validation”, but what to change and where. Plus a summary written for people who will not read the technical section.

  4. Retest

    Once your team has worked through the findings, we verify the fixes and reissue the report. A finding is only closed when we have confirmed it. This is included, not a separate engagement.

What you get

A report your engineers can act on without calling us

The test is only worth what the write-up makes possible. Findings are verified before they reach you — we do not pass on scanner output and leave you to work out which half is real.

CRITICAL HIGH MEDIUM LOW
  • Executive summary. One page, plain language, for the people approving the budget rather than fixing the bug.
  • Findings with evidence. Requests, responses and screenshots — enough for your team to reproduce it themselves.
  • Severity with reasoning. Why this is high and that one is low, in terms of your environment rather than a generic score.
  • Specific remediation. What to change, where, and what to verify afterwards.
  • Same-day alerts on critical issues. Anything actively exploitable is raised immediately, not saved for the report.
  • Retest and reissue. Fixes verified, report updated, findings closed on evidence.
  • A debrief call. Walking your engineers through the findings, so the fixes land properly.

FAQ

Questions we get asked first

How long does a test take?

It depends on scope. A single web application is typically a matter of days; a full internal network assessment takes longer. We give you a duration and a price with the scope document, before you commit — not an hourly meter.

How soon can you start?

Tell us what you need tested and we will come back with availability and a scope. Urgent work — a pending release, a compliance deadline, an incident — is worth saying up front, because it changes how we sequence things.

Which industries do you work with?

The methodology does not change much between sectors; what changes is the threat model and the compliance context. If you have specific regulatory requirements, tell us during scoping so the report is structured to satisfy them.

How do you handle our data?

We work under NDA as standard. Engagement data is kept encrypted, shared only through channels you agree to, and destroyed on an agreed schedule after delivery. We do not retain client data to build marketing material from it.

Will testing take our systems down?

Testing is conducted to avoid disruption, and anything genuinely destructive is only performed with explicit written approval and an agreed window. If you would rather we tested a staging environment, that is a legitimate choice — we will tell you what it means for coverage.

What does the report actually look like?

An executive summary, then one entry per finding with evidence, reproduction steps, severity and remediation — the format shown at the top of this page. We are happy to send a redacted sample before you commit to anything.

Get in touch

Tell us what you need tested

A short description of the systems and what you are worried about is enough to start. We will come back with scope, timing and a price before anything is committed.

Request a scoping call
support@i-h4ck.pro