Web application
Single-page apps, server-rendered apps, admin consoles. Authentication, authorization, business logic, file uploads. OWASP WSTG aligned.
Each surface gets its own deep methodology. Choose the test type that matches your stack, or the compliance framework your auditor expects.
Manual exploitation against the agreed scope, with working PoCs and retest included.
Single-page apps, server-rendered apps, admin consoles. Authentication, authorization, business logic, file uploads. OWASP WSTG aligned.
Broken object-level authorization, mass assignment, batched query abuse, schema introspection, rate-limit bypass. OWASP API Top 10 aligned.
Static analysis, Frida instrumentation, certificate pinning, secrets in storage, IPC abuse, biometric bypass. OWASP MASVS aligned.
External perimeter, internal lateral movement, Active Directory, ADCS, kerberoasting, segmentation. PTES + OSSTMM.
IAM blast radius, exposed object storage, metadata-service abuse via SSRF, cross-account chains, control-plane logging gaps.
Firmware extraction, hardware interfaces (JTAG/UART/SPI), radio protocols (BLE/Zigbee), companion app, cloud backend.
Named methodology, CVSS severity mapping, retest evidence, and a signed attestation letter in the format auditors accept.
TSC CC6.1, CC6.6, CC7.1, CC8.1. Named methodology, CVSS 4.0 severity, retest evidence, attestation letter.
Req 11.3.1 (internal) and 11.3.2 (external). CDE scoping, segmentation validation, QSA-ready deliverables.
Security Rule §164.308(a)(8). ePHI system scope, BAA execution before testing, OCR audit readiness.
Annex A.8.8 and A.8.29. ISMS boundary alignment, 2022 control mapping, certification-body evidence.
CA-8 and NIST SP 800-115. Rules of engagement, 3PAO-compatible deliverables, Moderate and High baselines.
A 30-minute call gets you a fixed-fee proposal in writing. No NDA needed for the first call.