← All services

Penetration testing across your real attack surface

Applications and APIs, mobile, infrastructure, cloud and GenAI/LLM systems: scoped together when attack paths cross boundaries. Each finding includes evidence your engineers can reproduce and a concrete remediation path.

Fixed price per scope. The quote lists the systems, roles, environments, testing window and deliverables before work starts.

19+Years in IT & security
1,000+Vulns Reported
7Published CVEs

Need evidence for assurance or compliance?

ISO 27001, SOC 2 and NIS2 work has its own page: a fixed 10-working-day window, findings mapped to relevant controls and a retest status note for your assurance team.

See the audit evidence service →

What I test

One engagement, scoped to what you actually run. These are not separate products; we agree the surface in the scoping call.

Web, APIs and mobile

Web and mobile applications, plus the APIs behind them, across guest, user, administrator and tenant boundaries.

Cloud and infrastructure

External perimeter and all public-facing assets, plus a cloud configuration review across AWS, GCP and Azure.

Full scope and attack chains

External assets, identities and trust boundaries tested as one system. It is time-boxed like a pentest, but follows attack paths across components instead of reviewing each one in isolation.

LLM and GenAI

Prompt injection, tool authorization, cross-user data boundaries and RAG isolation. I hold the AI/ML Pentester certification and have separately completed DeepLearning.AI's Red Teaming LLM Applications course.

What's included

  • Written scope and rules of engagement
  • Manual testing backed by bug-bounty methodology
  • Findings report with severity, reproduction, business impact
  • Retest of fixes included
  • Debrief call with your engineering team

Common reasons to test

  • Preparing for ISO 27001, SOC 2 or PCI audit
  • Shipping a new product and want a second opinion before launch
  • Reviewing authorization across roles or customer tenants
  • Validating a sensitive workflow or new API before launch
  • Replacing a broad scan with reproducible manual evidence
  • You need NDA + signed SoW before engaging

What I need from your team

  • A representative test environment or an agreed production-safe plan
  • Test accounts for every role, ideally two per role
  • A technical contact for access and scope questions
  • Someone who owns remediation after delivery
  • Consultancies can use the separate white-label service

You receive

  • Executive summary: board-ready, 1-2 pages
  • Technical report: findings, reproduction steps, business impact, remediation
  • Risk-ranked roadmap: prioritized fix order, not just CVSS
  • Retest pass: fixes verified, sign-off note for the auditor
  • Live debrief call: every finding walked through with your engineers

See the deliverable before you buy

A full anonymised sample report: executive summary, findings mapped to ISO 27001 and SOC 2 controls, proof-of-concept and concrete remediation. No email required.

Download the sample report (PDF) →

"We were preparing for our ISO 27001 certification and needed a proper pentest. Martín found issues that our previous vendor and automated scans had completely missed. Clear report, zero fluff, and he took the time to walk our devs through every fix."

Fintech client, ISO 27001 certification