Skip to content

Services

Penetration testing for applications, networks and cloud.

Choose the assessment that matches your systems and the decision in front of you. Every engagement includes manual testing, the full report and a walkthrough with your developers, and one retest of the reported findings on eligible services, requested within 60 days of the report. Internal network and Active Directory retests are scoped separately when required.

Request a scoping call

Not sure which one you need? That is what the scoping call is for.

Engagements start at $5,000 CAD. That is the starting point, not the price of every scope: what you need tested sets the rest, and you get a fixed price in writing before anything begins.

Where to start

Which one do you need?

A web application test includes the API calls that application makes. API testing is for an API that stands on its own. If you are not sure where one ends and the other starts, the scoping call settles it.

Side by side

What each one covers, and what you learn

  • Web Application Testing

    Best when
    A release, an audit or an enterprise customer is asking how your application was tested.
    Covers
    Authentication and sessions, access control between users and tenants, input handling, business logic, and the API calls the application makes.
    You learn
    Whether one user can reach another's account or data, and the specific changes that stop it.
    Web Application Testing in detail
  • Mobile Application Testing

    Best when
    The app handles accounts, payments or personal data, on one platform or both.
    Covers
    Local storage, transport security, session handling, deep links and other platform interaction, code protection, and the APIs behind the app.
    You learn
    What the app gives away on a device an attacker controls, and what the backend accepts from a modified client.
    Mobile Application Testing in detail
  • External Network Testing

    Best when
    You have not reviewed your perimeter since the last migration, acquisition or new remote-access service.
    Covers
    Discovery of what you expose, service enumeration, leaked credentials, login surfaces, exposed management interfaces, and exploitation of what is found.
    You learn
    A confirmed inventory of what you expose, and which of those exposures lead somewhere.
    External Network Testing in detail
  • Internal Network Testing

    Best when
    You want to know what one phished credential or one compromised laptop is worth to an attacker.
    Covers
    Active Directory attack paths, credential harvesting, lateral movement, segmentation and host configuration.
    You learn
    Whether a route from an ordinary foothold to domain privilege exists, how far it was demonstrated, and the changes that break it.
    Internal Network Testing in detail
  • API Testing

    Best when
    The API is the product, or several clients and integrations depend on it.
    Covers
    REST, GraphQL and SOAP endpoints tested role by role, including object and function level authorization, token scope, mass assignment and rate limits.
    You learn
    Which roles can reach data and actions they should not, laid out as an authorization matrix.
    API Testing in detail
  • Cloud Security Testing

    Best when
    You are launching, migrating, or changing identity and access, or the environment was built by many hands and nobody has compared it with what was intended.
    Covers
    Identity and access, privilege escalation paths, storage exposure, network rules, compute and serverless configuration, and logging.
    You learn
    The paths from a foothold to data or administrative control, each marked as demonstrated or inferred, with each fix given as the policy or setting to change.
    Cloud Security Testing in detail

We test systems by hand and write up what we find. We do not sell managed detection, awareness training or compliance consulting.

Find out what an attacker would find first.