Services

Three surfaces, one team.

Applications and infrastructure, AI systems, connected devices. Most firms cover one of these well. Products shipping AI features on connected hardware need all three tested together, by people who talk to each other.

Application and infrastructure

Vulnerability assessment and penetration testing across everything your users touch.

From $3,000

Starter VAPT, $3-5K: one web app or API. Standard VAPT, $6-8K: app, API and cloud together.

See pricing

What we test

  • Web and mobile apps
  • APIs and integrations
  • Network and cloud configuration

Where teams usually start

  • A first test before a fundraise or launch.
  • An enterprise deal that asks for proof of testing.
  • A compliance or customer request.

Standards we follow

Web applications
OWASP Web Security Testing Guide (WSTG) and Application Security Verification Standard (ASVS).
APIs
OWASP API Security Top 10.
Mobile apps
OWASP Mobile Application Security Verification Standard (MASVS) and Testing Guide (MASTG).
Network and cloud
NIST SP 800-115 and the Penetration Testing Execution Standard (PTES).

AI security

Testing for the failure modes that arrive with LLMs and agents, before your users find them.

From $8,000

AI or IoT tier, $8-10K: LLM features and agents.

See pricing

What we test

  • Prompt injection and jailbreaks
  • Agent and tool misuse
  • Data leakage through model outputs

Where teams usually start

  • An AI launch: a new assistant, agent or LLM feature.
  • An enterprise buyer asking how your AI features were tested.
  • A fundraise where the product is built around AI.

Standards we follow

AI and LLM systems
OWASP Top 10 for LLM Applications and MITRE ATLAS.

IoT security

Hardware, firmware and the radios in between, tested the way an attacker with the device in hand would.

From $8,000

AI or IoT tier, $8-10K: a connected device and its firmware.

See pricing

What we test

  • Firmware extraction and analysis
  • Hardware debug interfaces
  • BLE, Zigbee and MQTT

Where teams usually start

  • A connected device getting ready to launch.
  • An enterprise customer asking for evidence of device testing.
  • A compliance or customer request.

Standards we follow

IoT devices
OWASP IoT Security Testing Guide (ISTG).

How an engagement runs.

Every engagement follows the same path, so you always know what happens next and who is doing it. Testing starts only after you approve the scope, the environment and the testing window.

  1. Day 0

    Talk

    You tell us what you’re shipping and what prompted the test: a fundraise, an enterprise deal, an AI launch. We confirm we’re the right fit.

  2. Day 1

    Scope

    A 30-minute scoping call with the testers. A fixed-price scope reaches your inbox within 48 hours, with the environment and window for you to approve.

  3. Day 4 to 5

    Test

    Trial runs and confirmations from our side, then testing starts in the agreed environment and window: automated attacks first, then manual testing of every page and endpoint in scope.

  4. Day 12 to 14

    Report and certificate

    A technical findings and vulnerability report for your engineers, plus a managerial report for leadership. Every finding is rated Critical, High, Medium, Low or Informational. Your certificate is issued the same day.

  5. After

    Fix check

    A live walkthrough with the testers, support for your developers while they fix, then a fix check recorded on your certificate.

What you receive.

Two reports by email, a call with the people who did the work, and help until your fixes are checked. Each finding comes with the request, the impact and the fix, written for engineers.

Technical report
Each finding with the affected endpoint, the request that proves it, the impact, a severity rating and the fix.
Managerial report
Overall risk in plain words, findings by severity, and what to fix first, for founders and leadership.
Live walkthrough
The testers who found each issue explain it and answer your developers’ questions.
Remediation support
Open support and guidance for your developers while they fix.
Fix check, included
We re-test what you fixed, and the certificate record shows the date.
Certificate
A unique ID and QR code anyone can check, valid for 3 to 6 months.

Tools for breadth. People for depth.

Tools find the known patterns quickly. People find the logic flaws tools miss. Every engagement uses both, in that order.

Automated attacks.

Best-of-market tools sweep everything in scope for known weaknesses first, so testers spend their time where judgement matters.

Manual testing.

Testers then work through every page and endpoint in scope by hand, looking for broken logic, weak access rules and issues that only appear when chained.

Testers you talk to.

Every engagement is run by certified security testers. No account managers in between: the people who find an issue explain it and check your fix.

Proof you can share, not a PDF in a drawer.

Investors and enterprise buyers ask whether you’ve been tested. The certificate answers in seconds, and its expiry date keeps your security from going stale.

Unique ID
Every certificate is issued against one engagement and one scope.
QR check
Anyone can scan it to confirm it’s genuine and still valid.
3 to 6 months
Validity is set per engagement. When it expires, a retest renews it.

The public record shows the holder, the scope, the testing window, the issue and expiry dates, and the fix check date once done.

It records one engagement and its scope. It is not a CERT-In audit certificate, an ISO 27001 certification or a SOC 2 report, and it does not claim the system has no vulnerabilities.

Sample layout. Real certificates carry a live verification code.

One test, or a steady rhythm.

Start with a single engagement. When your product changes faster than a certificate lasts, retests and an annual contract keep your assurance current.

One-time testing

One scoped engagement, from the scoping call to the certificate, at a fixed price agreed in writing before testing starts.

Half when you approve the scope, half on delivery of the report.

Retesting

The first fix check is included in every engagement. A later full retest, for example to renew a certificate, is priced against the original fee.

70% of the original fee, or 50% on an annual contract.

Annual contract

Testing that keeps pace with your releases, agreed once for the year, with full retests at the lower rate.

Three scheduled tests and one ad hoc test a year.

Several products or surfaces at once? Enterprise engagements start at $25K and are scoped around your roadmap.

Tell us what you’re shipping.

A fundraise, an enterprise deal, an AI launch. Send a line about your product and we come back with a fixed-price scope within 48 hours.