Home/Services/Penetration testing
penetration testing

Testing that proves impact — not a scanner export.

Certified engineers attack your apps, APIs and networks the way a real adversary would, then hand you evidence, CVSS scores and a fix list your team can action. A free retest confirms the holes are closed.

OWASP · PTES · NIST 800-115 CVSS 3.1 scored findings Free remediation retest
what we test

Coverage across your whole attack surface

Scope one asset or all of them. Everything is tested by hand, safely, with your rules of engagement.

Web applications

Auth, sessions, access control, injection, business logic and the OWASP Top 10 — end to end.

APIs & GraphQL

REST and GraphQL: broken object-level auth (IDOR), mass assignment, rate-limit and token flaws.

Mobile apps

iOS and Android: insecure storage, cert pinning, API misuse and reverse-engineering exposure.

External network

Internet-facing perimeter: exposed services, misconfigurations and known-CVE exploitation.

Internal network

Assumed-breach and lateral movement: AD, privilege escalation and segmentation testing.

Cloud & config

AWS, Azure and GCP review: IAM, storage exposure, secrets and hardening gaps.

full coverage

Penetration testing for everything you run

63 services across every target, industry and compliance framework. If it has an attack surface, we test it.

By target & technology

AI & LLM Application

Adversarial testing of LLM-powered apps, chatbots and agents: prompt injection, data leakage, jailbreaks and unsafe tool use.

Machine Learning Model

Security review of ML pipelines and models: data poisoning, model theft, evasion and inference attacks.

IoT Device

Full-stack IoT testing across hardware, firmware, wireless and the cloud backend that controls your devices.

OT, ICS & SCADA

Safe, carefully-scoped security testing of industrial control systems, PLCs and SCADA networks.

Cloud Penetration Testing (AWS, Azure, GCP)

Attacker's-eye testing of your cloud accounts: IAM, exposed services, privilege escalation and lateral movement.

Cloud Security Configuration Review

A guided review of your cloud baseline against CIS benchmarks and provider best practice.

Kubernetes & Container

Security testing of your clusters, images and container runtime — from a breached pod to cluster-admin.

External Network

Testing of your internet-facing perimeter — the services an attacker sees before they've broken in.

Internal Network

Assumed-breach testing from inside your network: how far can an attacker with a foothold really get?

Active Directory

Deep testing of your AD and identity layer — Kerberos, delegation, ADCS and the road to Domain Admin.

Wireless & Wi-Fi

Testing of your Wi-Fi and wireless networks: rogue access points, weak encryption and guest-network bleed.

Red Team

A goal-based, multi-vector attack simulation that tests your people, process and technology together.

Social Engineering & Phishing

Controlled phishing, vishing and pretext campaigns that measure how your people respond to real attacks.

Physical

On-site testing of your physical security: tailgating, badge cloning, locks and access to sensitive areas.

Thick Client & Desktop App

Security testing of installed desktop applications: local storage, IPC, updates and their server APIs.

Blockchain & Smart Contract

Manual and tool-assisted audit of smart contracts and dApps: reentrancy, logic flaws and economic attacks.

Secure Source Code Review

Manual, context-aware review of your source code to find the flaws black-box testing can't reach.

DevSecOps & CI/CD Pipeline Security

Security review of your build and deployment pipeline — where a compromise ships straight to production.

Software Supply Chain Security Testing

Assessment of the third-party code, dependencies and vendors your software quietly trusts.

SaaS & Multi-Tenant

Testing built for SaaS: tenant isolation, role and plan enforcement, and the flaws that leak data across customers.

PCI DSS

Scoped penetration testing that satisfies PCI DSS requirement 11.4 for your cardholder data environment.

Automotive & Embedded

Security testing of embedded systems and connected vehicles: CAN bus, ECUs, firmware and telematics.

Thin Client & VDI

Testing of thin clients and virtual desktop infrastructure (Citrix, VMware, RDS) for breakout and privilege escalation.

Mainframe

Security assessment of z/OS mainframe environments, RACF/ACF2 and legacy transaction systems.

ATM & POS

Testing of ATMs and point-of-sale systems: jackpotting, black-box attacks, and payment-flow tampering.

Medical Device

Security testing of connected medical devices and their apps and backends, aligned to FDA and MDR guidance.

VoIP & Telephony

Testing of VoIP and unified-communications systems: SIP abuse, toll fraud, eavesdropping and PBX takeover.

Serverless & Cloud Function

Security testing of serverless apps (Lambda, Azure/GCP Functions): event injection, over-privileged roles and secrets.

Firmware

Deep analysis of device firmware: extraction, reverse engineering, hardcoded secrets and insecure updates.

Hardware

Physical and logical attacks on device hardware: debug ports, chip-off, side-channel and tamper resistance.

Purple Team

Collaborative red-and-blue exercise that improves your detection and response in real time.

Penetration Testing as a Service

Continuous, platform-delivered pentesting with real-time findings, retests and year-round coverage.

Continuous

Ongoing, scheduled testing that keeps pace with your release cycle instead of a once-a-year check.

Threat Modeling

Structured analysis of your architecture to find design-level risks before a line of code is attacked.

DeFi Protocol

End-to-end review of DeFi protocols: economic attacks, oracle manipulation, MEV and cross-contract risk.

SAP & ERP

Security testing of SAP and ERP platforms: authorization abuse, RFC/gateway exposure and segregation-of-duties.

Remote Access & VPN

Testing of the remote-access edge: VPNs, gateways and MFA that attackers hit first for initial access.

OSINT & Attack Surface

An outside-in map of everything an attacker can find about you: exposed assets, leaked credentials and shadow IT.

Phishing Simulation

Realistic, measurable phishing campaigns that train your people and prove where the human risk is.

Secrets & Credential Exposure

A hunt for exposed secrets across your code, pipelines, cloud and history that hand attackers the keys.

By industry

Fintech & Banking

Security testing built for financial platforms: payment flows, APIs, PCI DSS and DORA obligations.

Healthcare

Testing for healthcare systems: EHR/EMR, patient portals, medical devices and HIPAA-aligned scope.

E-commerce & Retail

Testing engineered around checkout, payment integrations, coupons and account security for online stores.

SaaS & Technology

Testing tuned for SaaS: multi-tenant isolation, RBAC, integrations and the SOC 2 / ISO evidence you need.

iGaming & Online Gambling

Security testing for online casinos and betting platforms: wallet, bonus abuse, RNG integrity and licensing.

Crypto & Web3

Full-stack security for crypto businesses: exchanges, wallets, smart contracts and the bridges between them.

Insurance

Testing for insurers: policy and claims platforms, broker portals, customer data and regulatory scope.

Government & Public Sector

Testing for public-sector systems: citizen services, sensitive data and NIS2 / national security requirements.

Education & EdTech

Testing for schools, universities and EdTech: student data, LMS platforms and sprawling, open networks.

Manufacturing & Industrial

IT/OT testing for manufacturers: production networks, ICS/SCADA and the IT-to-plant-floor boundary.

Telecom

Testing for telecom operators: core networks, signalling, subscriber data and large service platforms.

Energy & Utilities

Testing for energy and utilities: grid and OT systems, smart meters and critical-infrastructure resilience.

Logistics & Transport

Testing for logistics and transport: tracking platforms, EDI/API integrations, fleet and warehouse systems.

Legal & Professional Services

Testing for law and professional firms: document systems, client confidentiality and high-value data.

Startup

Right-sized, fast penetration testing that gets startups secure and audit-ready without enterprise overhead.

By compliance & framework

Also covered: Web app · API & GraphQL · Mobile · WordPress · OWASP Top 10

methodology

How an engagement runs

A repeatable, standards-based process — every step documented so you can audit exactly what we did.

01

Scope & rules of engagement

We agree targets, test windows, credentials and safety limits in writing. You know exactly what will and won't be touched.

signed RoENDAtest window
02

Recon & mapping

We enumerate the real attack surface: endpoints, parameters, roles and trust boundaries — the map an attacker would build first.

03

Manual exploitation

Hands-on testing of each vector, including business logic and chained attacks. Read-only where it matters, with a proof of concept for everything we confirm.

OWASPPTESMITRE ATT&CK
04

Reporting

Executive summary for leadership plus a technical write-up per finding: impact, CVSS, reproduction steps and a concrete, prioritised fix.

05

Free retest

After you patch, we re-verify each finding and issue an updated report and attestation letter — included in the engagement.

attestation letter
what you get

Deliverables you can act on and audit

No 200-page PDF of scanner noise. Two clear documents, plus the paperwork compliance asks for.

Get a scoped quote

Executive summary

Risk in business terms — what could happen, and what to fix first.

Technical findings

Each with CVSS score, affected assets, reproduction steps and proof of concept.

Remediation guidance

Concrete, prioritised fixes written for developers — not generic advice.

Retest report & attestation

Updated report after fixes plus a signed letter for clients, partners and auditors.

engagement types

Pick the depth you need

Indicative starting points — the final quote is fixed and set after a short, free scoping call.

Essential
from€2,500

One focused asset — a single web app or API.

  • Single web app or API
  • OWASP-based manual testing
  • Full report + free retest
Request quote
Most popular Standard
from€4,500

App + API + auth, the way most breaches actually happen.

  • Web app + API + auth flows
  • Business-logic & chained attacks
  • Exec + technical report, retest
  • Attestation letter
Request quote
Advanced
from€8,000

Full-scope or assumed-breach across your estate.

  • Multi-asset / network / cloud
  • Assumed-breach & lateral movement
  • Debrief workshop + retest
Request quote

* Indicative starting prices in EUR. Final scope and fixed price are agreed after a free scoping call.

faq

Questions we get before an engagement

Will testing take my site down?
No. We test safely within agreed rules of engagement, keep destructive actions off production, and coordinate any higher-risk checks with you in advance.
How long does a pentest take?
A single web app is typically 3–5 working days of testing plus reporting. Larger, multi-asset engagements run 2–3 weeks. You get an exact timeline at scoping.
Do you need credentials or source code?
For most web and API work we test authenticated as several user roles, so yes — test accounts help us find the impactful access-control bugs. Source code is optional and deepens coverage.
Is the retest really free?
Yes. Once you've patched, we re-verify every finding and issue an updated report and attestation letter at no extra cost, within a set window after delivery.
Can you help with compliance (PCI, ISO, SOC 2)?
Our reports and attestation letters are built to satisfy PCI DSS, ISO 27001 and SOC 2 pentest requirements. Tell us the framework and we'll align the deliverables.
$ safetybis pentest --scope your-app

Book a pentest that proves where you stand.

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day — and in under 30 minutes for active incidents.