Applications + APIs
Product penetration testing
Authentication, authorization, business logic and data access across the product and the services behind it.
- Web and API testing
- Identity and role boundaries
- Business-logic abuse
- Cross-customer access
Penetration testing and security review
Choose a focused penetration test, a broader security audit, or an AI and agent assessment. Every engagement includes hands-on testing, prioritized findings, detailed evidence, and reporting your engineering and assurance teams can use.
On-premises · Hybrid · AWS · Microsoft Azure · Google Cloud
Assessment + advisory services
A single engagement may cross several of these areas. We shape the work around the product, its deployment and the decision your team needs to make.
Applications + APIs
Authentication, authorization, business logic and data access across the product and the services behind it.
External exposure
Public applications, infrastructure and third-party paths reviewed from an unauthenticated attacker’s position.
Native software
Client-side controls tested with the APIs and services they call, not as an isolated binary review.
AI safety + security
We test whether AI features stay inside their data, action and safety boundaries under adversarial use, untrusted retrieved content and model or prompt changes.
Architecture + deployment
We review the product and the environment beneath it—from on-premises and hybrid deployments to all three major public clouds.
After the assessment
We help the responsible team turn a finding into the right engineering change, then test the completed fix against the original path.
AI safety use cases
We examine how models, retrieval, memory, tools, people and ordinary application controls behave together. The objective is a demonstrated failure path and a control the product team can improve.
Retrieval authorization, tenant isolation, memory, training-data exposure and sensitive output handling.
Cross-tenant disclosure · secret leakage · unsafe retrievalTool permissions, service identity, approval steps, transaction limits and human escalation controls.
Unauthorized actions · privilege expansion · approval bypassPrompt injection, jailbreak resistance, harmful-output controls, abuse paths and policy enforcement across languages and channels.
Safeguard bypass · harmful content · product misuseRetrieved-content poisoning, model and prompt changes, plugin trust, evaluation gaps and unsafe fallback behavior.
Poisoned context · untrusted components · silent regressionsRAG applications · Copilots · Customer-service agents · Transactional agents · Content generation · Evaluation pipelines
How an engagement works
We agree what may be tested, how far proof should go and who to contact before any active work starts.
Start with the launch, customer request or risk question the assessment must support.
Agree targets, accounts, exclusions, test windows and stopping conditions in writing.
Reproduce credible paths and report urgent issues while the assessment is still under way.
Deliver prioritized findings, work through engineering questions and record the status of agreed fixes.
Detailed reporting
Agreed scope and exclusions, methods, material findings, demonstrated business impact, priority, limitations and unresolved risk.
Affected assets, prerequisites, exact reproduction steps, retained evidence, control failure and specific remediation guidance.
Dates, tested boundaries, finding status and approved evidence that can support customer reviews, procurement diligence and internal governance.
Recommended controls, ownership, finding status and the result of agreed fix validation.
New assessment
Send a short description of the system, the reason for testing and your target date. We will reply with the questions needed to shape the scope.
Scope an engagement