Application security
Free website security check
We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.
Application security
Web application penetration testing
We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.
Application security
API security testing
An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.
Application security
Mobile application penetration testing
We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.
Application security
Secure code review
We read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.
Infrastructure and cloud
Cloud & Kubernetes security assessment
We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.
Infrastructure and cloud
Infrastructure penetration testing
We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.
Infrastructure and cloud
External attack surface assessment
We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.
Infrastructure and cloud
CI/CD & supply chain security
We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.
Adversary simulation
Red team operations
A full-scale exercise. We play a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.
Adversary simulation
Purple team exercises
We and your defenders work side by side: we execute an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.
Adversary simulation
Social engineering assessment
We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.
AI, Web3 and cryptography
AI & LLM security testing
If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.
AI, Web3 and cryptography
Smart contract audit
Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.
AI, Web3 and cryptography
Cryptography review
We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.
Programs and assurance
Bug bounty program management
A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.
Programs and assurance
Vulnerability disclosure program (VDP)
A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.
Programs and assurance
Continuous penetration testing
Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.
Programs and assurance
Compliance-driven penetration testing
A penetration test scoped and documented to match what an auditor, a regulator or a large customer expects to see in a report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2. Whether the report is accepted is decided by them.
Services of interest
Not sure yet
Choose this if you do not know which service you need. Describe the task in your own words, and we will suggest the service in the reply.