Find the holes before someone else does.

Your system is already running. I go through it as an attacker and write down what I find — with severity, and with what should be done about it.

WHAT IS INCLUDED

  • Vulnerability testing of website, API and login flow
  • Access-control review: can one user reach another one’s data?
  • Session and authentication handling
  • A review of data handling and GDPR compliance
  • Dependencies and known vulnerabilities in what you already run
  • Written report with findings, severity and concrete remedies
  • Retest once the remedies are in place

WHO IT SUITS

For the system that is already running. Especially if it has grown over time, if several people have had their hands in it, or if nobody quite knows who has access to what any more.

HOW IT GOES

  1. Scope and authorisationWe agree in writing on what is to be tested and what is not to be touched, before anything happens. Without that it is not a test.
  2. MappingWhat is exposed, which entry points exist, what you are actually running.
  3. TestingI try to get in, and to get further once I am in. Everything is logged as it happens.
  4. Report and retestThe findings are written down with severity and remedies. Once you have fixed them, I run the same thing again.

PRICE

Priced by scope, which depends on how large the system is and what is to be tested. The scoping call is free.

See the pricing

THE PROOF

None of the six deliveries on the front page is a penetration test — saying otherwise would be dressing up a record that is otherwise true. The basis is the education: a bachelor in cybersecurity, IT and ethical hacking, with a thesis on breaking language models commissioned by Telenor. The security review that is part of every single delivery above is the same job, done on my own systems before they are handed over.