03 · Security Testing
Penetration Testing
Findings you can reproduce, prioritized by real impact.
Human-led penetration testing against your application, API and authentication surfaces. Every finding ships with reproduction steps, evidence, business impact and a concrete fix, plus free retesting once you have remediated.
The context
Why this matters
Automated scanners find known-pattern issues. They do not find broken object-level authorization, tenant isolation failures, business logic abuse, or the auth flow that lets a trial user reach a paid customer's data. Those require someone who understands what your product is for.
We use AI analysis to do what machines are genuinely better at: enumerating the full attack surface, reading every route handler in the repository, and reconciling five tools that disagree. A consultant then proves or discards every candidate. Nothing unverified reaches your report, which is why our reports are short.
Our testing is manual-first, with tooling used to widen coverage rather than to generate the findings. We work from an authenticated position across every role your product defines, because the interesting failures in SaaS are almost always authorization failures, not missing headers.
Reports are written for engineers. Each finding has a reproduction path someone on your team can walk through, a severity justified by exploitability and business impact rather than a raw CVSS number, and a remediation recommendation specific to your stack. Retesting is included, a report that never gets verified is not security work.
What is covered
Scope of the engagement
- 01
Web application testing
Authentication, session management, authorization boundaries, injection, SSRF, file handling, deserialization, client-side issues, and business logic abuse across every user role.
- 02
API testing
REST, GraphQL and gRPC surfaces, BOLA/IDOR, mass assignment, rate limiting, schema abuse, introspection exposure, versioned and undocumented endpoints.
- 03
Multi-tenancy & isolation
Focused testing of tenant boundaries, the single highest-impact failure class in B2B SaaS, and the one enterprise security reviewers ask about most.
- 04
Authentication & SSO
Password flows, MFA bypass, session fixation, JWT handling, OAuth and OIDC implementation, SAML assertion handling, and SCIM provisioning.
- 05
Mobile application testing
iOS and Android clients, local storage, certificate handling, API abuse from a modified client, and platform-specific misconfiguration.
- 06
Retest & verification
After you remediate, we re-test every finding and reissue the report with verified fix status. Included in the engagement, not billed separately.
What you receive
Deliverables
Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.
- Executive summary written for non-technical stakeholders and boards
- Detailed technical findings with reproduction steps and evidence
- Severity ratings justified by exploitability and business impact
- Stack-specific remediation guidance for each finding
- Free retest and reissued report confirming fix status
- Customer-shareable attestation letter for your security questionnaires
Questions
Penetration Testing FAQ
We prefer a production-like staging environment with representative data, which lets us test destructively without risk. Where only production is available we agree strict rules of engagement, rate limits, excluded actions, a named contact reachable throughout, and a defined stop condition.
Yes. The report, the scope statement and the retest evidence are structured to serve as evidence for ISO 27001 Annex A 8.8 and 8.29 and for the SOC 2 Common Criteria around vulnerability management. If we are also running your certification programme, we map it for you.
We issue a customer-shareable attestation letter alongside the full technical report. The letter confirms scope, dates, methodology and remediation status without disclosing exploitable detail, which is what enterprise security reviewers actually need.
A scoped target list, test accounts for every user role, any API documentation you have, and a technical contact for questions. Where the environment is IP-restricted we will need allowlisting for our testing ranges.
Often paired with
ISO 27001 Certification
End-to-end ISO 27001 implementation: gap analysis, ISMS build, evidence and audit support, right through Stage 2.
Read more02SOC 2 Readiness
Type I and Type II readiness: control design, evidence discipline and auditor coordination, without the busywork.
Read more04Cloud Security Assessment
AWS, Azure, GCP, DigitalOcean, Linode and Vultr reviews covering IAM, exposure, data protection, logging and workloads.
Read moreKnow exactly what an auditor, and an attacker, would find.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.