penetration testing · by surface

Pentest, scoped to your surface.

Each surface gets its own deep methodology. Choose the test type that matches your stack, or the compliance framework your auditor expects.

01. by surface

Six surfaces.

Manual exploitation against the agreed scope, with working PoCs and retest included.

Web application

Single-page apps, server-rendered apps, admin consoles. Authentication, authorization, business logic, file uploads. OWASP WSTG aligned.

API (REST + GraphQL)

Broken object-level authorization, mass assignment, batched query abuse, schema introspection, rate-limit bypass. OWASP API Top 10 aligned.

Mobile (iOS + Android)

Static analysis, Frida instrumentation, certificate pinning, secrets in storage, IPC abuse, biometric bypass. OWASP MASVS aligned.

Network (external + internal)

External perimeter, internal lateral movement, Active Directory, ADCS, kerberoasting, segmentation. PTES + OSSTMM.

Cloud (AWS / GCP / Azure)

IAM blast radius, exposed object storage, metadata-service abuse via SSRF, cross-account chains, control-plane logging gaps.

IoT + embedded

Firmware extraction, hardware interfaces (JTAG/UART/SPI), radio protocols (BLE/Zigbee), companion app, cloud backend.

02. by framework

Built for your audit framework.

Named methodology, CVSS severity mapping, retest evidence, and a signed attestation letter in the format auditors accept.

SOC 2 penetration test

TSC CC6.1, CC6.6, CC7.1, CC8.1. Named methodology, CVSS 4.0 severity, retest evidence, attestation letter.

PCI DSS penetration test

Req 11.3.1 (internal) and 11.3.2 (external). CDE scoping, segmentation validation, QSA-ready deliverables.

HIPAA penetration test

Security Rule §164.308(a)(8). ePHI system scope, BAA execution before testing, OCR audit readiness.

FedRAMP penetration test

CA-8 and NIST SP 800-115. Rules of engagement, 3PAO-compatible deliverables, Moderate and High baselines.

Ready to scope a pentest?

A 30-minute call gets you a fixed-fee proposal in writing. No NDA needed for the first call.