Offensive security testing of the systems you build and operate — web applications, APIs, external infrastructure, source code, and the attack surface of systems that rely on language models.
| Assessment | Focus |
|---|---|
| Web Application | Authentication, authorization, injection, business logic, session management, application configuration |
| API | Object- and function-level access control, excessive data exposure, authentication, rate limiting, third-party integrations |
| Source Code Review | Line-by-line review of the submitted code: authentication flows, input validation, secret handling, and trust boundaries |
| External Infrastructure | Internet-exposed attack surface: service exposure, TLS configuration, headers, and undocumented entry points |
| Cloud & Configuration | Access policies, stored credentials, object storage, and recurring configuration errors |
| AI System Review | Prompt injection, data leakage through the model, access control over knowledge bases, and agent integration security |
Every assessment is mapped to the following frameworks. This mapping makes test results comparable across cycles and usable as internal compliance evidence.
| Framework | Used for |
|---|---|
| OWASP Top 10 | The ten web application risk classes that form the testing baseline |
| OWASP API Security Top 10 | API-specific risks: BOLA, BFLA, mass assignment, resource consumption |
| OWASP LLM Top 10 | Risks in language-model-based systems: prompt injection, data leakage, agent abuse |
| OWASP ASVS | Verification of application security controls at the level agreed during scoping |
| OWASP WSTG | The web application testing step guide that serves as our execution reference |
| MITRE ATT&CK | Mapping of attacker techniques and tactics for findings with detection implications |
| NIST CSF 2.0 | Placement of findings within the organizational risk management framework |
| ISO/IEC 27001 | Relevance of findings to the information security controls under audit |
| PTES | Testing phase framework: scoping, intelligence, exploitation, reporting |
| CVSS | Measurable severity scoring for each finding, rather than scoring by impression |
Duration is set during the scoping call — it depends on the number of assets, depth of review, and environment availability. The figures below are indicative only:
| Scale | Indicative | Best suited for |
|---|---|---|
| Focused | 2–4 business days | A single application or API with a narrow scope |
| Standard | 5–10 business days | Multiple applications, APIs, and source code review |
| In-depth | 2–4 weeks | Many assets, a large engineering team, or compliance objectives |
We do not perform: denial of service, high-volume stress testing, social engineering or phishing against employees, physical attacks, or testing of third-party assets without written authorization. For third-party systems connected to your assets, authorization must be arranged before testing begins.