- Home
- Services
Six services, one sequence
Most companies do not need all of this at once. They need the right one, in the right order, delivered by people who will still be around when it needs revisiting.
Pick the problem you actually have
Each of these works as a standalone engagement, and each is designed to slot into a longer programme if you want one. Click through for what is involved, what you get, and what it costs you in your team's time.
Web application penetration testing
We attack your web apps and APIs the way a real adversary would, then show your developers exactly how to fix what we find.
- Web apps
- REST & GraphQL
- Auth & sessions
- Business logic
Android & iOS penetration testing
Android and iOS break in different places. We test both, on real devices, and we do not stop at the app boundary.
- Android
- iOS
- API layer
- Reverse engineering
Network penetration testing
External and internal testing that answers the only question that matters: once an attacker has a foothold, how far do they get?
- External
- Internal
- Active Directory
- Lateral movement
AI security testing
Prompt injection, data leakage, tool abuse and model supply chain risk — tested against your real deployment, not a demo notebook.
- LLM apps
- Prompt injection
- Agents & tools
- RAG leakage
Threat detection
Detection engineering across endpoint, identity, cloud and network telemetry — tuned until every alert is worth reading.
- Detection engineering
- MITRE ATT&CK
- Alert triage
- Threat hunting
Red teaming
A goal-based adversary simulation against your people, processes and technology — measured against a real objective.
- Objective-based
- Social engineering
- Physical
- Purple-team debrief
If you are not sure where to start
Almost every company should begin in the same place. Identity hardening and tested backups close the majority of realistic attack paths, and both are cheap relative to what they prevent.
- Harden identity first. MFA everywhere, least privilege, and an end to standing admin rights. This is the highest return on effort available to almost anyone.
- Prove your backups. A restore test is the difference between an incident and an extinction event. Do it before you need it.
- Find your exposure. An assessment tells you what an attacker can already see. It is usually cheaper than the surprise.
- Add detection. Once the fundamentals are in place, monitoring turns a breach into an incident you can respond to.
- Then prove it to others. Compliance and reporting get much easier when the controls already exist and the evidence collects itself.
Not sure which one you need?
Tell us what is worrying you and we will tell you honestly where to start — including when the answer is "nothing yet".