What we test
Testing, organized by the surface rather than the package
Most engagements combine two or three of these. Each page says what the test covers, the classes of finding it usually surfaces, and exactly what access it needs on day one, because a tester blocked for a day has lost a fifth of the engagement.
Web applicationAuthenticated testing of a web application against the logic an attacker would actually abuse: who can reach what, whose data is whose, and what happens when a request arrives out of order.APITesting the API as the primary attack surface rather than as plumbing behind a user interface, including the endpoints the interface never calls.Cloud infrastructureTesting the cloud account itself: what an attacker reaches after one credential leaks, and how far identity and network configuration let them go.External and internal networkTesting the network perimeter from outside, and the internal network as though a foothold has already been established. PCI DSS requires both; most other frameworks are satisfied with the external half.AI and LLM featuresTesting the AI surface of a product as a security surface: where untrusted content reaches a model, what the model is allowed to do with tools, and what a crafted input can make happen.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.