Every engagement is hands-on keyboard, human-in-the-loop adversarial-style testing, led by David Porcello and a team who understands how each finding impacts your business.
OWASP GenAI Security Project aligned
Applications built on language models have a new trust boundary: the model itself, and everything it can read, call, or write. Testing covers direct and indirect prompt injection, tool and agent abuse, data exfiltration through retrieval and memory, guardrail bypass, and the conventional web and API weaknesses that surround the model.
OWASP WSTG and ASVS aligned
Authenticated and unauthenticated testing of web applications and the APIs behind them, including REST, GraphQL, and websocket back ends. We focus on what automated scanners miss: broken object and function-level authorization, business-logic abuse, multi-step workflow flaws, and the places where authentication and session handling quietly diverge from design.
PTES and NIST SP 800-115 aligned
External testing covers everything reachable from the internet: exposed services, remote-access gateways (VPN, ZTNA, SASE), mail, DNS, and shadow assets that often turn up during enumeration. Internal testing starts from an assumed breach, typically a standard user workstation or VPN account, and works toward the crown jewels through lateral movement, credential abuse, and privilege escalation.
AWS, Azure, and GCP
Cloud testing looks at the environment the way an attacker with a leaked key or a compromised developer laptop would: IAM and identity misconfiguration, over-privileged roles, exposed storage and services, metadata and instance-credential abuse, and cross-account/service paths that can connect a small foothold to the whole estate.
Assumed breach to domain admin
Windows domains remain the most reliable path from a single compromised host to the entire organization. Testing covers domain and forest enumeration, credential and hash attacks, Kerberos abuse, ADCS misconfiguration, delegation, trust relationships, EDR/AV bypass, and attack paths that only a skilled tester can uncover.
Windows desktop applications
Desktop applications carry assumptions that web apps abandoned years ago: trust in the client, secrets on disk, proprietary protocols, and client-side checks that only exist in the UI. Testing covers local storage and memory, inter-process communication, protocol interception and manipulation, and the back-end services the client talks to.
iOS and Android, OWASP MASVS aligned
On-device and back-end testing together, because the interesting findings are usually in how the two interact. Coverage includes local data storage, keychain and keystore use, transport security and certificate pinning, platform-permission misuse, and reverse engineering of the application binary to recover secrets and hidden functionality.
Hardware to cloud
Connected devices are tested end to end: the hardware and its debug interfaces, the firmware and what it stores, the local radio and network services, the mobile or web apps that manage it, and the cloud platform it reports to.
Binary and protocol analysis
When documentation and source code aren't available, reverse engineering provides the answers. Static and dynamic analysis of binaries, firmware, and proprietary protocols to identify vulnerabilities, recover embedded secrets, and build reliable proof-of-concept exploits that demonstrate real impact.
Most work is a fixed-scope, fixed-price engagement: we agree on targets, testing windows, and rules of engagement up front, and the price doesn’t move unless the scope does. We offer black-box, grey-box, and white-box testing, and for teams that ship continuously, a recurring cadence with a retained scope is available.
When the test exists to satisfy a requirement, it’s scoped to that requirement from the start. Engagements can be aligned with compliance frameworks including PCI DSS, SOC 2, HIPAA, and ISO 27001. Reports include the attestation and methodology your auditor, customer, or partner needs.
Most first conversations are a short call to work out the coverage that is right-sized for your business. Drop us an email to get started