Home / Penetration testing services
Training, code review, and the rest
Additional Services
Penetration testing is what we do. But a test tells you what is broken today, and teams often want help making the next release better — so we also do the following, usually alongside a test rather than instead of one.
Secure code review
Reading the source for flaws black-box testing cannot reach: authorization logic that is correct in one path and missing in another, cryptographic misuse, unsafe deserialisation, injection in code paths no interface exposes, and secrets committed where they should not be.
Most valuable on the parts of a system that matter most — authentication, authorization, payment handling, tenant separation — rather than as an everything-everywhere exercise. We will tell you where the budget is worth spending.
Secure development lifecycle advisory
Practical help embedding security into how your team already works: where to put gates engineers will not route around, what to automate and what genuinely needs a human, how to triage findings without drowning, and what “secure by default” looks like in your stack.
Grounded in having taught roughly around 5,000 developers developers, and in seeing what survives contact with a real release schedule.
Threat modelling and architecture review
Working through a design before it is built, or an architecture before it is extended: trust boundaries, what crosses them, what each component is authorised to do, and where one compromised element would give an attacker more than it should.
Most useful early — when a design decision still costs a conversation rather than a rewrite — and for AI features, where excessive agency is usually an architectural choice rather than a coding mistake.
How these fit
These are complements, not a separate practice. If you are choosing where to start and your application has never been tested, start with the test — it tells you what is actually exploitable, which is the fastest way to know whether the deeper work is worth doing.
Our penetration testing services · talk to us about what you need.
The test cases behind this service
Device and embedded work has its own catalogue: firmware, hardware debug interfaces, device identity and the protocols devices speak.
37 test cases across 7 categories.
Firmware Extraction and Reversing
Device Application Vulnerabilities
Device Identity and Access
Exposed Debugging Interfaces
Side Channel Attacks
Denial of Service
Network Traffic
The full catalogue is at Attacks & Tests, and the coverage matrix shows which published standards these map onto. How much access the testers are given is a separate question — see testing modes.
Tell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.