Security Assessment

SECURITY ASSESSMENT

Vulnerability testing that finds the gaps and ranks the fixes

Penetration testing and security assessments across web, mobile, API, cloud and network, delivered with a ranked remediation report your engineers can ship against.

6 areas

Security assessment coverage

4 hrs

Critical finding escalation

Re-test

Included in every engagement

WHAT WE TEST

Six security assessment areas we cover

Web application penetration testing

OWASP Top 10 coverage plus business logic flaws, authentication and session handling, injection attacks, access control issues and configuration weaknesses. Manual testing alongside automated scanning to catch what automated tools miss.

Mobile application security

iOS and Android apps tested for reverse engineering resistance, local storage security, API communication, runtime protection and platform-specific weaknesses including Keychain, KeyStore and biometric implementations.

API security testing

REST and GraphQL APIs tested against the OWASP API Top 10 covering broken authentication, excessive data exposure, broken access control, mass assignment, injection and security misconfiguration. Both authenticated and unauthenticated test paths.

Cloud infrastructure review

AWS, GCP and Azure environments reviewed against CIS Benchmarks and provider security best practices. IAM policies, networking, storage configuration, secrets management, logging and monitoring all covered.

Network penetration testing

External and internal network testing covering perimeter exposure, lateral movement, privilege escalation and data exfiltration paths. Black-box and authenticated approaches available depending on the threat model.

Source code review

Static analysis (SAST) plus manual code review for high-risk components. Catches issues that runtime testing misses, especially around authentication, cryptography, authorisation logic and dependency vulnerabilities.

FRAMEWORKS

Frameworks and methodologies we work to

Testing follows established frameworks so results map cleanly into your security programme.

OWASP Top 10

Web application testing

OWASP API Security Top 10

REST and GraphQL APIs

OWASP Mobile Top 10

iOS and Android

NIST CSF

Programme-level assessments

PTES

Methodology and rules of engagement

CIS Benchmarks

Cloud and infrastructure baselines

ISO 27001 / SOC 2

Control mapping on request

FISC / APPI

Japanese financial services and PII

WHAT YOU GET

The report and what's in it

Every vulnerability testing engagement ends with a written report structured so your team can act on it without asking us follow-up questions.

Executive summary

Plain-language risk overview for the board, customers, auditors or whoever needs to see findings without technical detail.

Technical findings

Each issue documented with CVSS severity score, full reproduction steps, screenshots and the affected components.

Ranked remediation guidance

Findings ordered by risk so your engineers know what to fix first, with specific recommendations rather than generic best-practice pointers.

Re-test on findings

One re-test included to verify fixes have closed each finding, with a clean re-test report you can hand to auditors.

HOW WE HANDLE FINDINGS

Confidentiality and critical findings

Security findings get handled with the seriousness they deserve.

NDA before scope

NDAs signed before any technical detail is shared. The scope of work agreement names exact systems, IP ranges and test windows so testing stays inside the agreed bounds.

Encrypted reporting

Reports delivered encrypted to named recipients only, through dedicated secure channels rather than general business tools.

Critical finding escalation

Anything rated critical during testing gets escalated to your nominated contact within four hours. Testing pauses on the affected system if the issue presents active risk.

Disclosure handling

Where findings affect third-party software or services, coordinated disclosure follows industry standards on a timeline you control.

WHEN TEAMS COME TO US

When security testing makes sense

Before a product launch

You're about to go live and want an independent check before customer data starts flowing. We work to your launch timeline with re-test scheduled before the public release date.

Before signing a major customer

An enterprise prospect requires a pen test report as part of their vendor security review. We deliver a clean report you can hand to their security team within their evaluation window.

After a security incident

Something went wrong and you need to know if anything else is exposed. Scoped quickly, focused on the most likely lateral risks first, with daily status during testing.

For compliance certification

ISO 27001, SOC 2, PCI DSS or FISC readiness work, with control mapping and audit-ready evidence prepared alongside the technical testing.

As a regular security cycle

Annual or quarterly testing on a retainer basis, with results tracked against the previous cycle so improvement is measurable over time.

PRICING

How security testing pricing works

Tests are scoped per engagement so the price matches the work.

01

Single application test

Fixed price covering one application (web, mobile or API) or one cloud environment, with the full report and one re-test of fixed findings included.

02

Multi-scope engagement

Fixed price covering multiple applications, network and cloud together. Typical for pre-launch reviews of a whole platform or annual security audits.

03

Ongoing security retainer

Monthly retainer for continuous testing across releases, scheduled re-tests and ad-hoc reviews when needed.

04

Compliance-specific assessment

Scoped against the target framework with control mapping and audit-ready evidence included alongside the technical findings.

FAQS

Common questions about security testing

Yes. Our security team based across Japan and Sri Lanka holds combinations of OSCP, CEH, CISSP and CREST certifications, with specialist credentials in cloud security and application security. CV summaries of the testers assigned to your engagement are shared during scoping so you know exactly who is doing the work.

Critical findings are escalated to your nominated contact within four hours with reproduction details and a recommended interim mitigation. If the issue presents active risk, testing pauses on the affected system until your team has decided how to respond and authorised next steps.

Test windows and methods are agreed in writing before any testing begins. Most engagements use a staging environment for invasive testing and switch to read-only or rate-limited checks on production. Risk to production systems is documented and signed off as part of the scope agreement.

A single web application test typically runs five to ten working days, with kick-off, testing and report delivery inside that window. Multi-scope engagements run two to four weeks. Compliance-specific assessments run longer because of the control mapping and evidence work involved.

Yes. One re-test of all reported findings is included in every engagement, with a clean re-test report confirming which issues are closed. Additional re-tests after later fix rounds are available at a reduced rate as part of the same engagement.

Yes. ISO 27001, SOC 2, PCI DSS, FISC and Japanese APPI alignment are supported as scoped engagements, with framework experience built from work with regulated businesses across Japan and the wider region. Control mapping is prepared alongside the technical testing so your auditor receives evidence in a format their framework expects.

GET IN TOUCH

See what attackers would find in your system

Tell us what you want tested. We come back within three working days with a scoped quote covering testing methodology, timeline, the certified testers we'd put on it and what the report will include. NDA in place before any technical detail is shared.

Request a sample report