Security testing services

Four focused services, all delivered through manual assessment by certified practitioners. Every engagement includes formal reporting and a verification retest.

Core service

Web Application & API Penetration Testing

A manual, authenticated assessment of your application and its supporting APIs, focused on the flaws that cause real compromise: broken access control, authentication weaknesses, and business-logic abuse.

What we test

  • Authentication, session lifecycle, and token handling
  • Authorisation across every user role and tenant boundary
  • Business-logic abuse and workflow bypass
  • Injection, input validation, and output encoding
  • API endpoint enumeration and object-level authorisation
  • File upload handling and server-side request forgery
  • Transport security and security header configuration

What you receive

  • Executive summary written for non-technical stakeholders
  • Per-finding reproduction steps a developer can follow
  • CVSS v3.1 vectors with impact and likelihood rationale
  • Specific, actionable remediation guidance
  • A verification retest and updated remediation-status report

Typical engagement

Two weeks of testing for a mid-sized application, followed by a remediation window and retest. Exact duration is confirmed during scoping.

Mapped to OWASP Top 10 · OWASP API Security Top 10 · OWASP ASVS · CVSS v3.1 · STRIDE

Emerging risk

AI / LLM Application Security Testing

Most teams ship AI features far faster than they security-review them. An LLM feature is an API endpoint with an unusually permissive trust boundary — and it needs adversarial testing on its own terms.

What we test

  • Direct and indirect prompt injection
  • System-prompt and context-window disclosure
  • Insecure output handling leading to XSS or code execution
  • Excessive agency in tool-calling and agent workflows
  • Sensitive data leakage through model responses
  • RAG pipeline poisoning and document-boundary bypass
  • Rate limiting, cost abuse, and denial-of-wallet exposure

What you receive

  • Reproducible attack payloads with observed model behaviour
  • Severity assessment reflecting real business impact
  • Guardrail and architectural recommendations, not just filters
  • A verification retest after mitigations are deployed

Who this is for

Teams shipping customer-facing chat, retrieval-augmented search, or agentic features — particularly where the model can access internal data or trigger actions.

Mapped to OWASP Top 10 for LLM Applications · CVSS v3.1

Infrastructure

Cloud & AI Infrastructure Security Review

A configuration and privilege review of the infrastructure your application runs on. Cloud misconfiguration rarely appears in a code review — but it is a leading cause of data exposure.

What we review

  • IAM roles, policies, and privilege-escalation paths
  • Object storage exposure and access-control configuration
  • Network segmentation, security groups, and public surface
  • Secret storage, rotation, and hardcoded credential exposure
  • Logging, monitoring, and audit-trail coverage
  • Model endpoints, inference APIs, and vector database access
  • Encryption at rest and in transit

What you receive

  • Prioritised findings with exploitability context
  • Configuration-level remediation steps per provider
  • Benchmark alignment summary
  • A verification retest after changes are applied

Providers covered

Amazon Web Services, Google Cloud Platform, and Microsoft Azure — with current security certifications held across all three.

Mapped to CIS Benchmarks · Provider security best-practice frameworks

Broad coverage

Vulnerability Assessment

Where penetration testing goes deep on a defined target, a vulnerability assessment goes broad across your estate — identifying and prioritising known weaknesses at scale.

What it covers

  • External attack-surface discovery and enumeration
  • Known-vulnerability and outdated-component identification
  • Service, version, and configuration exposure
  • Certificate and transport security posture
  • Manual triage of every reported result

How it differs from a pentest

A vulnerability assessment tells you where known weaknesses exist across a wide surface. A penetration test proves what an attacker can actually chain together and achieve on a specific target. Most organisations benefit from both — assessment for coverage, testing for depth.

Why manual triage matters

Automated tools produce substantial false positives. Every result we report has been manually verified, so your engineering time goes to real issues.

CVSS v3.1 severity scoring · 100% manual triage

Engagement models

Point-in-time or continuous.

Project engagement

A defined assessment against an agreed scope, with a fixed timeline and deliverable. Suited to pre-launch validation, customer security reviews, audit requirements, and annual testing cycles.

Recurring programme

Scheduled testing aligned to your release cadence, so material changes are assessed as they ship rather than once a year. Suited to teams shipping continuously or operating under ongoing compliance obligations.

Not sure which service fits?

Describe your application and your reason for testing — a customer requirement, an upcoming launch, an audit — and we will recommend an approach.