Find the holes before someone else does

We test your app, APIs and cloud the way an attacker would, write up each finding so a developer can fix it, help ship the fixes - and then test again, so nothing is closed on a promise.

In every finding
  • Steps to reproduce
  • The fix, as code
  • A retest before it closes

What we test

Whatever an attacker could reach. The scope picks from these, and it is agreed before anything is touched.

A finding, written the way your developers need it

Not a scanner export. Each finding is one page a developer can act on and whoever sets priorities can rank. This is the one from the report above, in full.

Northwind audit, finding NW-01

Order API returns other customers’ invoices when the ID is changed

Severity
High
Where
/api/orders/:id/invoice
Class
Broken access control
Status
Retested
Impact

Any signed-in customer can read any other customer’s invoices - names, delivery addresses and order totals - by changing one number in a request. No special tools needed.

In plain words, so it can be ranked without a call.

Why High

Easy to find, needs only an ordinary account, and exposes personal data for every customer who has ever ordered.

The reasoning is written down, so you can argue with it.

Reproduce
  1. 1. Sign in as test customer A.
  2. 2. GET /api/orders/10482/invoice 200, A’s invoice
  3. 3. GET /api/orders/10481/invoice 200, B’s invoice

Exact requests, so a developer sees it for themselves in minutes.

Fix

Check the order belongs to the signed-in user before returning it. The same check was missing on the receipt and shipping-label routes; both are in the same pull request.

The change itself, in your code - not a link to a checklist.

Retest

The request from step 3 now returns 403 for every order the caller does not own, on all three routes. Customer A’s own invoice still loads.

Closed only after we have tried again.

How an audit runs

Five steps, in this order. A report-only audit stops after the third; ours carries on until the fixes are in and hold.

  1. 1

    Scope

    What is in and out, which environment, the test window, and who to call if something looks wrong. Staging where it can be.

    You get a written scope
  2. 2

    Test

    Hands-on testing against that scope. Scanners cover ground; they are not the result.

    You get same-day word on anything High
  3. 3

    Report

    Every finding with impact, steps and a fix, ranked by what an attacker would reach first - and walked through with your team.

    You get the report, and a call
  4. 4

    Fix support

    We help your developers ship the fixes: reviewing their changes, or writing the patch ourselves where that is quicker.

    You get reviewed pull requests
  5. 5

    Retest

    The same attacks, run again. A finding is marked closed only when it actually is.

    You get a retest summary

Questions we get asked

What do you test?

Web apps, APIs, mobile apps, cloud configuration, auth and sessions, and dependencies. The scope is agreed in writing before anything is touched, and most audits cover some of these, not all.

Do we just get a report?

No. Every finding comes with steps to reproduce and a fix. We then help your team ship the fixes and retest each one before it is marked closed.

Will testing disturb production?

The environment and the test window are agreed during scoping, staging is used where it can be, and there is a named person to call if something looks wrong.

How are findings ranked?

High, Medium or Low, by how easily an attacker could reach it and what it would expose - with the reasoning written into each finding, so you can disagree with it.

Can the report help with compliance?

It can support your own compliance work, as a record of what was tested, what was found and what was fixed and retested. It is not a certification.

How is it priced?

Tell us what is in scope and we come back with a timeline and a price - not a discovery call first.

Want to know what someone could find?

Tell us what you run and what worries you - we come back with a scope, a timeline and a price.

Scope an audit