Penetration testing and security review

Test the systems that carry real business risk.

Choose a focused penetration test, a broader security audit, or an AI and agent assessment. Every engagement includes hands-on testing, prioritized findings, detailed evidence, and reporting your engineering and assurance teams can use.

On-premises · Hybrid · AWS · Microsoft Azure · Google Cloud

Assessment + advisory services

Coverage follows the attack path.

A single engagement may cross several of these areas. We shape the work around the product, its deployment and the decision your team needs to make.

Applications + APIs

Product penetration testing

Authentication, authorization, business logic and data access across the product and the services behind it.

  • Web and API testing
  • Identity and role boundaries
  • Business-logic abuse
  • Cross-customer access

External exposure

Attack-surface assessment

Public applications, infrastructure and third-party paths reviewed from an unauthenticated attacker’s position.

  • Asset discovery
  • Exposed services
  • Public application paths
  • Validated impact

Native software

Mobile and desktop application testing

Client-side controls tested with the APIs and services they call, not as an isolated binary review.

  • iOS and Android
  • macOS and Windows
  • Local storage and IPC
  • Deep links and updates

AI safety + security

AI and agent security assessment

We test whether AI features stay inside their data, action and safety boundaries under adversarial use, untrusted retrieved content and model or prompt changes.

  • Prompt injection and retrieval poisoning
  • Sensitive data and tenant isolation
  • Misuse and harmful-output controls
  • Agent permissions and human oversight

Architecture + deployment

Security audit and risk assessment

We review the product and the environment beneath it—from on-premises and hybrid deployments to all three major public clouds.

  • On-premises and hybrid
  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud

After the assessment

Remediation and security advisory

We help the responsible team turn a finding into the right engineering change, then test the completed fix against the original path.

  • Root-cause review
  • Control and architecture guidance
  • Engineering working sessions
  • Fix validation

AI safety use cases

Test the AI inside the product—not as an isolated model.

We examine how models, retrieval, memory, tools, people and ordinary application controls behave together. The objective is a demonstrated failure path and a control the product team can improve.

Data boundaries

Can the system reveal data it should not know?

Retrieval authorization, tenant isolation, memory, training-data exposure and sensitive output handling.

Cross-tenant disclosure · secret leakage · unsafe retrieval
Action boundaries

Can an agent do more than the user is allowed to do?

Tool permissions, service identity, approval steps, transaction limits and human escalation controls.

Unauthorized actions · privilege expansion · approval bypass
Behavioral safeguards

Do misuse and safety controls hold under adversarial use?

Prompt injection, jailbreak resistance, harmful-output controls, abuse paths and policy enforcement across languages and channels.

Safeguard bypass · harmful content · product misuse
System integrity

What happens when the context, model or supply chain changes?

Retrieved-content poisoning, model and prompt changes, plugin trust, evaluation gaps and unsafe fallback behavior.

Poisoned context · untrusted components · silent regressions
Common systems

RAG applications · Copilots · Customer-service agents · Transactional agents · Content generation · Evaluation pipelines

How an engagement works

A clear scope, a controlled test and evidence your team can act on.

We agree what may be tested, how far proof should go and who to contact before any active work starts.

  1. Define the decision

    Start with the launch, customer request or risk question the assessment must support.

  2. Set access and limits

    Agree targets, accounts, exclusions, test windows and stopping conditions in writing.

  3. Test and communicate

    Reproduce credible paths and report urgent issues while the assessment is still under way.

  4. Report and support

    Deliver prioritized findings, work through engineering questions and record the status of agreed fixes.

Detailed reporting

One factual record for engineering, risk and assurance.

Decision summary

Agreed scope and exclusions, methods, material findings, demonstrated business impact, priority, limitations and unresolved risk.

Technical findings

Affected assets, prerequisites, exact reproduction steps, retained evidence, control failure and specific remediation guidance.

Assurance record

Dates, tested boundaries, finding status and approved evidence that can support customer reviews, procurement diligence and internal governance.

Remediation and verification

Recommended controls, ownership, finding status and the result of agreed fix validation.

New assessment

Scope your next engagement.

Send a short description of the system, the reason for testing and your target date. We will reply with the questions needed to shape the scope.

Scope an engagement