Services

Security testing at the core, engineering around it.

Our 14 security testing disciplines run through one authorized, non-interactive pipeline — consistent methodology, consistent reporting, no gaps between tools. Around that core sit the adjacent services teams ask us for next: quality engineering, cloud and infrastructure work, observability, and AI & data services — held to the same standards of evidence and delivery.

Security testing

14 disciplines, one engagement.

The core practice: every layer an attacker can reach, tested to the OWASP Testing Guide and verified by hand before it reaches your report.

SQL Injection

Automated and manual injection testing against every JMX-defined endpoint, GET and POST, with configurable risk/level depth and DB enumeration.

sqlmap-driven

Cross-Site Scripting

Reflected, stored, and DOM-based XSS across forms and parameters, plus a second opinion on SQLi, SSRF, command execution, and CRLF injection.

Wapiti-driven

Known CVEs & Misconfigurations

Template-driven scanning against thousands of known CVEs, exposed panels, default logins, and common misconfigurations.

nuclei-driven

SSRF & Blind Command Injection

Out-of-band detection via interactsh for server-side request forgery and blind command-injection paths that never return output directly.

interactsh OOB

JWT Forgery

alg=none downgrade, signature stripping, key confusion, and other JWT forgery techniques tested against real auth flows.

jwt_tool

Broken Access Control (IDOR/BOLA)

Cross-tenant access checks run against two live accounts on separate tenants — the only way to prove authorization boundaries actually hold.

Dual-account testing

Authentication Hardening

Login rate limiting, session fixation, logout invalidation, token expiry, and concurrent-session handling — with an optional real-password lockout check.

Auth flow analysis

Security Headers & CORS

HTTP security header coverage, cookie flags, and CORS policy review against origin-reflection and overly permissive configurations.

HTTP layer audit

TLS/SSL Configuration

Protocol, cipher suite, and certificate review — expired/weak certs, deprecated protocol versions, and insecure cipher negotiation.

testssl.sh-driven

Exposed Files & Content Discovery

Directory and file brute-forcing for exposed .git, .env, backups, API docs, and forgotten hidden endpoints.

ffuf-driven

Static Code Analysis (SAST)

Source-level scanning for injection sinks, unsafe patterns, and logic flaws before they ever reach a running deployment.

semgrep-driven

Secrets in Git History

Full git-history scanning for committed API keys, tokens, and credentials that git rm alone never actually removes.

gitleaks-driven

Vulnerable Dependencies

Known-vulnerable and deprecated package detection across the dependency tree via npm/pnpm audit, with CVE lookups on the full tree, not just top-level packages.

Supply-chain scan

Reconnaissance & Attack Surface Mapping

Port scanning, WAF/fingerprint detection, subdomain and URL discovery, JS-link extraction, and HTTP request-smuggling checks, chained into one pass.

sn1per-orchestrated

Quality engineering

Testing that isn't only about attackers.

Functional, exploratory, and performance testing — delivered with the same evidence trail and reporting discipline as the security work.

Web Application Testing

Functional coverage of user journeys, forms, and state transitions across browsers and viewports, with regression suites you keep.

Functional QA

Manual & Exploratory Testing

Charter-based sessions that find the edge cases automation never asserts on — broken flows, confusing states, content and usability issues.

Session-based

Test Automation

UI and API automation (Playwright, Cypress, REST-assured) with stable selectors, CI integration, and reporting your team can read.

CI-wired

Load & Performance Testing

k6, JMeter, or Gatling scenarios for throughput and latency percentiles, plus soak and spike tests — with bottleneck analysis, not just a graph.

Load · soak · spike

API Testing

Contract, schema, negative-path, and multi-step workflow testing against your OpenAPI spec or Postman collections.

Contract & workflow

Accessibility Testing

WCAG 2.2 AA audits with keyboard and screen-reader passes, prioritised findings, and concrete remediation guidance.

WCAG 2.2 AA

Cloud & infrastructure

The platform underneath the application.

Designed, built, migrated, and audited to the same security bar we test to. Two of these have dedicated engagement pages — follow the arrows.

Infra Migration →

Bare metal into any cloud, or one cloud platform to another — workload discovery, target architecture as IaC, wave-by-wave cutover with rollback, and an independent post-migration audit.

Bare metal → cloud · cloud → cloud

Database Migration & Design →

Data model and engine chosen from real access patterns, near-zero-downtime migration between cloud architectures, restore-tested backup and DR, and monitoring left in place.

Design · migrate · back up · monitor

Network Infrastructure Setup

VPC/VNet layout, subnetting and segmentation, private connectivity and VPN, firewalls, DNS, and load balancing — delivered as reviewable infrastructure-as-code, not console clicks.

Network as code

Cloud Architecture Design & Test

Reference architectures for scale and resilience, a Well-Architected-style review of an existing estate, then load- and failure-testing to prove it behaves under stress.

Design · review · test

DevOps Engineering & IaC

CI/CD pipeline design, Terraform / OpenTofu, and release automation, built with the same security discipline we test for.

IaC · CI/CD

Technical & Security Auditing

Independent audit of infrastructure, cloud configuration, and architecture against CIS benchmarks and the compliance regime that applies to you.

Infra & config audit

Observability & operations

Know before your users do.

Metrics, logs, traces, and alerting set up so problems surface as signals on a dashboard, not as support tickets.

Monitoring Setup

Golden-signal dashboards, centralised log aggregation, distributed tracing, and alert rules with thresholds tuned to be actionable rather than noisy.

Metrics · logs · traces

Monitoring Tool Integration

Datadog, Grafana / Prometheus, New Relic, ELK / OpenSearch, CloudWatch, or Azure Monitor — instrumented into your stack and wired through to on-call.

Datadog · Grafana · ELK

SLOs & Incident Readiness

Define SLOs and error budgets, set up alert routing and escalation, and write the runbooks for the failure modes that actually page you.

SLO · on-call

Application Performance Monitoring

Code-level tracing, slow-transaction and error-rate tracking, and per-release health so a regression is caught in staging, not by a customer.

APM

Managed Monitoring

Ongoing threshold tuning, alert triage, and a monthly reliability report on a retainer — so the setup doesn't rot the moment the project ends.

Retainer

AI & data services

The pipeline behind the model.

Sourcing, labeling, and moving data — and stress-testing the AI systems built on top of it, with the same adversarial mindset as the security work.

Data Collection & Sourcing

Scoped web and API collection with a sampling strategy, licensing and provenance tracking, deduplication, and PII handling built in from the start.

Sourcing · provenance

Data Annotation & Labeling

Image, text, audio, and document labeling against written guidelines, with multi-pass review, gold sets, and inter-annotator agreement tracked as a metric.

Guidelines · QA · gold sets

Data Pipeline Engineering

Batch and streaming ETL/ELT, orchestration with Airflow or Dagster, data-quality checks as a gate, and feature stores for downstream training and serving.

ETL/ELT · streaming

Model Evaluation & Red-teaming

Benchmark and task-based eval harnesses, bias and robustness checks, and adversarial prompt, jailbreak, and data-poisoning testing.

Eval · adversarial

RAG & LLM Application Development

Retrieval pipelines, prompt and guardrail design, an evaluation loop, and a deployment hardened against prompt injection and data exfiltration.

Retrieval · guardrails

AI System Security Testing

Prompt injection, tool and function-call abuse, training-data and model supply-chain risk, and output-handling flaws in AI-backed features.

AI red-team

Not sure which services you need?

See how we bundle these into solutions for common engagement types.