Offensive Security · CREST-Certified Team

Offensive penetration testing and red teaming.

We simulate real-world attackers across web applications, authenticated APIs, cloud infrastructure, Kubernetes clusters, and AI agent workloads. Manual, adversary-led testing that finds critical flaws before malicious actors do — backed by an executive summary, engineer-ready PoCs, and verified audit attestation.

CREST-certified team Manual adversary emulation Free 60-day retest Executive & technical reports Audit attestation included

Illustrative workflow, not live client activity. Testing is performed by experienced humans, not just scanners.

Offensive Security & Scope Triage

Calculate your penetration testing & red teaming scope.

Select your target technology stack and engagement objective to calculate the recommended offensive methodology, threat simulation depth, and delivery schedule.

Recommended Scope

Web Application & API Penetration Test

In-depth manual testing targeting business logic flaws, broken object-level authorization (BOLA/IDOR), session hijacking, and API data leakage under active adversarial conditions.

Methodology OWASP WSTG + API Top 10 + CREST Team
Timeline 5–7 Days Active Testing + 1 Day Reporting
Focus Area Pre-Release Attack Surface Validation
Retest Guarantee Free 60-Day Retest & Verified Attestation
✓ Free 60-Day Retest Included ✓ Letter of Attestation for Auditors ✓ Non-Disruptive Staging/Prod Windows ✓ CREST-Certified Manual Testing
Offensive Coverage

Offensive attack vectors we test and exploit.

Every assessment simulates real-world adversaries targeting critical business assets. We uncover chained attack paths across application logic, cloud identity, container runtimes, and AI workflows — pairing each finding with verifiable proof-of-concept exploits and engineer-ready remediation code.

Web Application Pentesting

Risk: Account takeover, BOLA, multi-tenant data leaks.

Manual testing of authentication flows, session handling, business-logic vulnerabilities, authorization bypasses, and SQL/Command injection aligned to OWASP WSTG.

REST & GraphQL API Pentesting

Risk: Silent bulk data exfiltration via exposed endpoints.

Targeted exploitation of Broken Object Level Authorization (BOLA), mass assignment, rate-limiting gaps, and improper asset management aligned to OWASP API Top 10.

Cloud Security & IAM Escalation

Risk: Single credential compromise yielding full cloud control.

Adversarial testing across AWS, GCP, and Azure: IAM role assumption, privilege escalation chains, exposed storage buckets, metadata service abuse (SSRF), and VPC peering vulnerabilities.

Kubernetes & Container Security

Risk: Pod compromise escalating to cluster and host node takeover.

RBAC privilege misuse, container escapes, vulnerable admission webhooks, insecure secrets mounts, and container supply chain weaknesses evaluated against CIS Benchmarks.

AI & LLM Red Teaming

Risk: Prompt injection, RAG data leakage, and tool hijacking.

Adversarial testing of LLM applications, indirect prompt injection, sensitive data leakage through RAG pipelines, and autonomous agent tool-calling boundary bypasses against OWASP LLM Top 10.

Compliance & Audit Attestation

Risk: Enterprise procurement blockers and failed compliance audits.

Conclusive, auditor-ready technical evidence and Letter of Attestation mapped to SOC 2 (CC7.1), ISO 27001:2022 (A.8.8, A.8.29), PCI DSS v4.0 (11.4), and APRA CPS 234.

Trigger Events

When engineering teams engage our offensive security team.

From pre-release attack surface validation to mandatory enterprise customer questionnaires and regulatory audits — we provide independent, rigorous adversary testing.

Pre-Launch Production Releases

New code · new attack paths

Validate new features, authentication revamps, or payment workflows before public exposure. Uncover business logic flaws automated CI/CD tools miss.

Annual Compliance Deadlines

SOC 2 · ISO 27001 · PCI DSS 11.4

Auditors demand recent independent technical testing evidence. We deliver reports that satisfy assessors without requiring back-and-forth clarifications.

Enterprise Customer Questionnaires

Vendor risk management proof

Enterprise procurement teams require an attestation letter confirming third-party penetration testing. Unblock six-figure enterprise sales cycles fast.

Cloud & Infrastructure Migrations

AWS · GCP · Azure · Kubernetes

Moving from VMs to Kubernetes or shifting cloud providers introduces new IAM, networking, and metadata exposure. We validate your new posture before cutover.

Production AI & Agent Deployment

LLMs · RAG · Tool-Calling Agents

Deploying customer-facing or internal LLM agents? We test against prompt injection, memory poisoning, unauthenticated tool execution, and data leakage.

Post-Incident Verification

Remediation closure · sibling flaws

Following a security breach or vulnerability disclosure, verify that the exploit vector is sealed and adjacent services are not vulnerable to the same technique.

Process

Our four-phase penetration testing process.

The entry point is a scoping conversation, not a price list. Day counts below are typical; your scoping call confirms exact numbers before anything is booked.

01 · 1 DAY

Scope & objectives

NDA signed, assets and objectives agreed in writing: what is tested, from where, with what access, and what "done" means.

02 · 1-2 DAYS

Planning

Threat surfaces mapped, accounts and environments provisioned, rules of engagement and escalation channel confirmed.

03 · 5-10 DAYS

Execution & reporting

Manual, hands-on testing with critical findings raised immediately, then a QA-reviewed report: exec summary plus full technical detail.

04 · INCLUDED

Follow-up & retest

Remediation walkthrough with your engineers, then every finding re-tested and the report updated to show verified closure.

Methodology: recognised standards, manual delivery.

Testing aligns to OWASP (Web Security Testing Guide, API Security Top 10, LLM Top 10), NIST SP 800-115, PTES and OSSTMM, delivered by a CREST-certified team. Automation is used for coverage; every reported finding is manually validated with proof-of-concept evidence, because scanner output is not a penetration test.

Deliverables

What you receive: an audit-grade report, twice over.

The report is the product. Every engagement produces two documents, written for two different readers, plus a verified retest.

Document 1 · for the board

Executive summary

A plain-language risk verdict your board, customers and auditors can read without a translator.

  • One-line security posture verdict with business impact
  • Findings count by severity band
  • What was tested, and what held up well
  • Recommended remediation order by urgency
Document 2 · for your engineers

Full technical report

Everything your team needs to reproduce, understand and fix each finding, without booking a call to decode it.

  • Exact locations: URLs, endpoints, resources, file paths
  • Proof-of-concept evidence and screenshots per finding
  • Business impact and severity rating per finding
  • Specific remediation steps with references
  • Written scope statement covering exactly what was assessed

Included in every engagement (Penva-grade de-risking bundle).

  • Free 60-day retest: Once you remediate findings, we re-test every finding and update your report with verified closure status
  • Letter of attestation: Executive verification on letterhead for SOC 2/ISO 27001 auditors and enterprise procurement security questionnaires
  • Remediation walkthrough session: Direct 1:1 screen-share session with your engineering team to review code and config fixes
  • Live critical alerts: Critical findings are raised within 2 hours of discovery, not held back until the final report delivery
  • Zero production disruption: Coordinated testing windows, non-destructive payloads, and emergency immediate-stop channel
  • NDA before scoping: All engagement data, credentials, and findings handled under mutual confidentiality and strict access controls
Severity rating

How we rate severity.

Findings are rated on two axes, impact and exploitability, so ratings are consistent and independent of any one environment. CVSS scores are available on request, but the matrix below is what drives your remediation order.

Impact \ Exploitability Easy Moderate Difficult
High Critical High Medium
Medium High Medium Low
Low Medium Low Low

Scroll the matrix horizontally to compare every severity band.

  • Critical Direct, practical path to sensitive data or platform control. Fix immediately; we raise these the moment they are validated.
  • High Serious weakness an attacker could realistically exploit to cause material business harm. Prioritise within days.
  • Medium Exploitable under specific conditions or as part of a chain. Schedule into the next remediation cycle.
  • Low Limited standalone impact, but reduces attacker effort when combined with other weaknesses.
  • Info No direct security impact; observations and hardening opportunities worth recording.
Who does the testing

Clear accountability from scope to retest.

Team-level credentials

Testing is performed by a CREST-certified team, with credential scope stated at team level and report QA built into the engagement.

Senior-led delivery

Your assessment is delivered by experienced, certified testers, not handed to the newest hire. The people who scope the engagement are the people who test and write the report.

Platform engineers who attack

We build production cloud, Kubernetes and AI platforms for a living, so we test yours from the inside out: architecture-aware, not checklist-driven.

Compliance

Compliance mapping with real control references.

Compliance managers don't need a test, they need evidence that satisfies specific controls. Our reports reference them directly. If a specific framework is your driver, see penetration testing for compliance for how a pentest evidences SOC 2, ISO 27001, Essential Eight and PCI DSS.

ISO 27001

A.8.8 · A.8.29 · A.5.23

Technical vulnerability management, security testing in development and acceptance, and cloud services security.

SOC 2

CC7.1

Detection and monitoring of new vulnerabilities and configuration changes, evidenced by independent testing.

PCI DSS v4.0

Requirement 11.4

External and internal penetration testing on a defined cadence and after significant changes.

APRA CPS 234

Information security testing

Systematic testing of information security controls, including those operated by third parties.

Essential Eight

ACSC maturity evidence

Validation that patching, privilege and application-control mitigations actually hold under attack.

Customer questionnaires

Procurement & vendor review

A recent independent report plus letter of attestation answers most security questionnaires in one attachment.

Scoping request

Request a penetration test scoping call.

Tell us what needs testing. We will reply within one business day with initial scoping questions and proposed call times. This form does not book a calendar slot.

What needs testing?
Environment

No price calculators, no spam. NDA before scoping. One reply, with substance.

Scope drives price. A short call establishes assets, environments and compliance drivers; you get a fixed-scope, fixed-price proposal to approve in writing before anything starts.

[email protected]

FAQ

Penetration testing FAQ.

How much does a penetration test cost?

Every engagement is scoped per engagement. A free scoping call establishes the assets, environments and compliance drivers in play, and we return a fixed-scope, fixed-price proposal sized to your environment. We don't publish anchor prices: scope drives price, and you approve it in writing before any testing starts.

How long does a penetration test take?

Most engagements run five to ten business days of active testing, plus one to two days of reporting and QA. The retest of remediated findings is typically one further day. The scoping call confirms an exact timeline for your scope before anything is booked.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is an automated sweep for known issues; it produces long lists and false positives. A penetration test is a manual, hands-on assessment in which experienced testers chain weaknesses the way a real attacker would, validate every finding with proof-of-concept evidence, and rate it by business impact. We use tooling for coverage, but every reported finding is manually verified.

Will testing affect our production environment?

We test staging or pre-production by default. Where production testing is required, it runs in coordinated windows with agreed rules of engagement, out-of-hours options and an immediate-stop channel. Denial-of-service testing is excluded unless explicitly scoped.

Is a retest included?

Yes. Every engagement includes a retest as a standard phase, not an add-on: once you remediate, we re-test each finding and update the report to show verified remediation status, so your auditors and customers see closure, not just discovery.

Are your penetration testers CREST-certified?

Yes. All testing is performed by a CREST-certified team. CREST is the internationally recognised accreditation body that enterprise procurement teams and auditors reference. Reports are written to the audit-ready standard assessors expect.

What methodology do you follow?

Testing aligns to recognised standards: OWASP (Web Security Testing Guide, API Security Top 10, LLM Top 10), NIST SP 800-115, PTES and OSSTMM, delivered by a CREST-certified team. Testing is manual and hands-on; automation is used for coverage, never as the deliverable.

What does the report contain?

Two documents: a board-ready executive summary with a plain-language risk verdict and business impact, and a full technical report where every finding includes exact locations, proof-of-concept evidence, business impact, specific remediation guidance and references. Findings are rated on our published Impact × Exploitability severity matrix; CVSS scores are available on request.

Is penetration testing required for ISO 27001, SOC 2 or PCI DSS?

Each framework expects independent technical testing as evidence: ISO 27001 controls A.8.8, A.8.29 and A.5.23; SOC 2 CC7.1; PCI DSS v4.0 Requirement 11.4; APRA CPS 234; and the Essential Eight all map to penetration testing outcomes. Our reports reference the controls your assessor will look for.

How often should we get a penetration test?

At least annually, and after any major change: a new product launch, significant architecture change, cloud migration or an incident. Many compliance frameworks and enterprise customer contracts specify annual testing as a minimum.

Which industries and locations do you serve?

SaaS, fintech, digital health and technology product companies, from scale-up startups to established businesses. Engagements are delivered remotely, with working hours that overlap your team wherever you are.

Do you sign NDAs before scoping?

Yes. We sign a mutual NDA before any scoping conversation, and all engagement material, including the report, is handled under agreed sensitivity controls.

Need evidence before the next questionnaire?

Testing is delivered by a CREST-certified team, retest included. Scope drives price; a short call settles both.