Agreement and scope
Bilateral NDA and proposal with scope, rules of engagement and windows defined in writing. Nothing starts without authorization.
Our team runs real intrusion tests on networks, applications and infrastructure to identify and exploit vulnerabilities before the adversary does.
Pentest is an authorized test in which specialists try to break into systems, networks or applications to find flaws before a criminal exploits them. It is not an automated scan: every finding is validated and exploited in a controlled way, to show the real impact.
We test the external perimeter, internal network and Active Directory, web applications and APIs, mobile apps and social engineering, in black box, gray box or white box modes, depending on the objective.
A predictable flow, under NDA, with the client informed at every step.
Bilateral NDA and proposal with scope, rules of engagement and windows defined in writing. Nothing starts without authorization.
Mapping of the attack surface and controlled exploitation of the flaws, following OWASP, PTES, MITRE ATT&CK and NIST SP 800-115.
Executive and technical reports with evidence, risk rating, impact and remediation guidance, delivered over an encrypted channel.
Secure destruction of data and access per NIST SP 800-88, with written confirmation and post-delivery support.
Every engagement starts with a bilateral NDA. We do not disclose client names, vulnerabilities or incidents without written authorization, and sensitive communication uses encrypted channels (Signal and PGP).
Complete APT attack simulations, with social engineering and physical and digital intrusion, to assess your organization's real resilience.
See the serviceCollection and analysis of open source information to map the attack surface, track threat actors and protect your digital exposure.
See the serviceWe continuously check whether data of your company or your social accounts is exposed on the dark web: credentials, documents and sensitive information.
See the serviceFast response, total confidentiality and field execution. No fluff.