SVC—INDEX
Penetration testing and offensive-security services.
The same quality process applies across every domain. Scope, access, methods, evidence, and limitations are adapted to the system being tested.
Scope an engagementSVC—01Web application penetration testingManual assessment of application logic, identity, authorization, data flow, and browser-facing attack surface.SVC—02API penetration testingAuthorization, object and property access, abuse paths, resource controls, inventory, and integration risk.SVC—03Network and infrastructure penetration testingExternal, internal, identity, segmentation, and hybrid infrastructure attack paths.SVC—04Red team and adversary emulationObjective-led exercises measuring prevention, detection, response, and business impact.SVC—05Mobile application penetration testingiOS and Android client, platform, local storage, transport, anti-tamper, and backend interaction.SVC—06Cloud penetration testingAWS, Azure, GCP, Kubernetes, IAM, services, workloads, and hybrid trust paths.SVC—07Security source-code reviewHuman review of security-critical code paths, architecture, data flow, and dangerous implementation patterns.SVC—08Wireless security assessmentAuthorized Wi-Fi, guest, corporate, segmentation, identity, and rogue-access scenarios.SVC—09AI and LLM system penetration testingModel-facing applications, agents, tools, retrieval, data boundaries, abuse paths, and MLOps controls.SVC—10Automotive security assessmentVehicle, ECU, telematics, mobile, API, cloud, diagnostic, and update-path security.SVC—11Social-engineering exerciseEthically bounded phishing, voice, messaging, and pretext scenarios with employee and business safeguards.SVC—12Physical security exerciseAuthorized access-control, reception, perimeter, tailgating, and evidence-handling scenarios.SVC—13Retest and remediation verificationFocused verification of originally reported findings and agreed fixes, with a clear comparison between original and current status.
OFFER—LOGIC
A commercial model that reflects uncertainty.
Scoped assessmentA fixed fee based on estimated effort and an outcome defined in advance.
Adversary exerciseTeam, duration, objectives, and rules of engagement are agreed in advance.
Specialist timeA day rate or capped time-and-materials model for work that cannot responsibly be priced as a fixed fee.
Continuous assuranceAnnual capacity, planning, prioritization, and retesting under clear rules.