Services
Penetration testing for applications, networks and cloud.
Choose the assessment that matches your systems and the decision in front of you. Every engagement includes manual testing, the full report and a walkthrough with your developers, and one retest of the reported findings on eligible services, requested within 60 days of the report. Internal network and Active Directory retests are scoped separately when required.
Not sure which one you need? That is what the scoping call is for.
Engagements start at $5,000 CAD. That is the starting point, not the price of every scope: what you need tested sets the rest, and you get a fixed price in writing before anything begins.
Where to start
Which one do you need?
- A customer-facing web application or SaaS product Web Application Testing
- An iOS or Android app Mobile Application Testing
- Systems reachable from the internet External Network Testing
- A network where one compromised account matters Internal Network Testing
- An API that partners, integrations or your own apps call API Testing
- Workloads running in Azure or AWS Cloud Security Testing
A web application test includes the API calls that application makes. API testing is for an API that stands on its own. If you are not sure where one ends and the other starts, the scoping call settles it.
Side by side
What each one covers, and what you learn
-
Web Application Testing
- Best when
- A release, an audit or an enterprise customer is asking how your application was tested.
- Covers
- Authentication and sessions, access control between users and tenants, input handling, business logic, and the API calls the application makes.
- You learn
- Whether one user can reach another's account or data, and the specific changes that stop it.
-
Mobile Application Testing
- Best when
- The app handles accounts, payments or personal data, on one platform or both.
- Covers
- Local storage, transport security, session handling, deep links and other platform interaction, code protection, and the APIs behind the app.
- You learn
- What the app gives away on a device an attacker controls, and what the backend accepts from a modified client.
-
External Network Testing
- Best when
- You have not reviewed your perimeter since the last migration, acquisition or new remote-access service.
- Covers
- Discovery of what you expose, service enumeration, leaked credentials, login surfaces, exposed management interfaces, and exploitation of what is found.
- You learn
- A confirmed inventory of what you expose, and which of those exposures lead somewhere.
-
Internal Network Testing
- Best when
- You want to know what one phished credential or one compromised laptop is worth to an attacker.
- Covers
- Active Directory attack paths, credential harvesting, lateral movement, segmentation and host configuration.
- You learn
- Whether a route from an ordinary foothold to domain privilege exists, how far it was demonstrated, and the changes that break it.
-
API Testing
- Best when
- The API is the product, or several clients and integrations depend on it.
- Covers
- REST, GraphQL and SOAP endpoints tested role by role, including object and function level authorization, token scope, mass assignment and rate limits.
- You learn
- Which roles can reach data and actions they should not, laid out as an authorization matrix.
-
Cloud Security Testing
- Best when
- You are launching, migrating, or changing identity and access, or the environment was built by many hands and nobody has compared it with what was intended.
- Covers
- Identity and access, privilege escalation paths, storage exposure, network rules, compute and serverless configuration, and logging.
- You learn
- The paths from a foothold to data or administrative control, each marked as demonstrated or inferred, with each fix given as the policy or setting to change.
We test systems by hand and write up what we find. We do not sell managed detection, awareness training or compliance consulting.