Free website security check
An external security check of one website, free of charge, with a report that is paid only when vulnerabilities are found.
Every assessment that finds vulnerabilities ends the same way: confirmed findings with evidence, a fix for each and a retest. What differs is the system under test and the question you need answered. The first step costs nothing: the website check is free.
01Where to start
If the right service is not obvious, find the closest question. If none fits, describe the situation in the request form and we will propose a scope.
We want to know whether our website can be broken into, and there is no budget yet
We are releasing a product and need to know it is safe to launch
An auditor, a customer or a regulator asks for a penetration test report
We do not know what we expose to the internet
We ship every week and an annual test is always out of date
We have added a language model or an agent to the product
We are about to deploy contracts that will hold funds
We want to know whether a real attack would be noticed
A researcher has reported a vulnerability and we have no process
Web, API, mobile and source code
An external security check of one website, free of charge, with a report that is paid only when vulnerabilities are found.
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Testing of REST, GraphQL, gRPC and WebSocket interfaces for broken authorisation, data exposure and abuse of business flows.
Testing of iOS and Android applications together with their backend: storage, transport, platform interaction and resistance to tampering.
Manual review of source code, supported by static analysis, for vulnerabilities that cannot be seen from outside.
Networks, cloud platforms, external perimeter
Assessment of AWS, Azure, Google Cloud and Kubernetes environments: identity, network exposure, data stores and paths from a foothold to full control.
External and internal penetration testing of networks and Active Directory: from an exposed service or a single workstation to control of the domain.
Discovery of everything your organisation exposes to the internet, known and forgotten, with each exposure verified by hand.
Assessment of the path from a commit to production: repositories, pipelines, runners, dependencies and build artefacts.
Goal-driven attacks against people, process and technology
A goal-driven simulation of a real adversary against people, process and technology, to test whether an attack would be detected and stopped.
A joint exercise: our operators execute attack techniques one by one while your defenders tune detection and response.
Controlled phishing, phone and messaging campaigns that measure how people and processes respond, with results by group and never by name.
LLM applications, smart contracts, cryptographic design
Adversarial testing of LLM applications, agents and MCP integrations: prompt injection, data leakage, tool abuse and escape from the intended task.
Line-by-line audit of smart contracts and protocol logic before deployment: manual review, invariant testing and review of the fixes.
Review of cryptographic design and implementation: protocols, key management, signatures and the generation of random values.
Bug bounty, disclosure, continuous and compliance testing
Design, launch and operation of your bug bounty program: policy, scope, reward table, triage and communication with researchers.
A public channel and a working process for vulnerability reports from outside: policy, security.txt, intake, triage and coordinated disclosure.
A standing team that tests every significant change and re-examines the perimeter on a schedule, instead of one report a year.
Penetration testing scoped and documented to serve as evidence for PCI DSS, SOC 2, ISO/IEC 27001, DORA and NIS2.
02Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.