Skip to content

Where Every Byte Matters

The test is the easy part. The report is what you actually buy.

Manual penetration testing for software companies and the organizations that depend on them. You find out what an attacker would reach, get a prioritised order to fix it in, and a retest that confirms the fixes landed.

Engagements from $5,000 CAD. Free scoping, and a fixed price in writing before any work begins.

  • OSCP
  • OSEP
  • OSWE
  • OSMR
  • BSCP
  • CRTO
  • OWASP Top 10
  • OWASP ASVS
  • OWASP Testing Guide
  • NIST SP 800-115
  • OSSTMM
  • WASC

Who you work with

You talk to the person testing your system.

Scoping calls, the engagement, the walkthrough and the retest are all the same people. That is the main advantage of a 3-person team: no account manager relaying questions to a contractor you never meet.

Kyle Moffat Founder and lead tester
  • OSCP
  • OSEP
  • CRTO
About the team

10,000+ hours of offensive security work across the team.

When to call

The moments a test earns its keep.

You are launching
An application, a major release, or a new customer-facing API.
You changed authentication or authorization
New single sign-on, MFA, roles, tenants or tokens.
A customer sent a security questionnaire
Or an enterprise deal is waiting on one.
Your auditor wants independent testing
SOC 2 and ISO 27001 auditors generally look for it inside the audit period.
Your cyber-insurance renewal asks
Whether a penetration test was done this year, and sometimes for the report.
You want an independent answer
Not the opinion of the team that built it.

What we answer

Four questions, with evidence.

  • Can someone take over an account?

    Password reset, session handling, MFA enrolment and the tokens behind them.

  • Can one customer reach another's data?

    Tenant and object-level authorization, tested at the API rather than only in the interface.

  • Can a normal user become an admin?

    Role boundaries, privileged functions and the business logic between them.

  • Can someone on the internet reach the inside?

    Your perimeter, your cloud configuration, and the path from one leaked key to the rest.

What you get

Findings you can act on, and proof they were fixed.

  • Validated findings. Each one confirmed by hand and supported by evidence.
  • A remediation order. Findings ranked by how exploitable each one is, what it means for your business, and what has to be fixed first.
  • Remediation written for your stack. Specific enough to hand to a developer, not a link to a vendor advisory.
  • A findings walkthrough. With the people who will fix them, included in every engagement.
  • One retest round. Of the reported findings within 60 days, included. You learn what actually closed.
  • What held up. The controls that resisted testing, recorded as plainly as the findings.

From a real engagement, anonymised

High

Temporary pre-MFA token accepted as a full credential

CWE-863 Incorrect Authorization

With only a user's password, an attacker could skip the second factor, replace the victim's authenticator and keep the account.

Found and fixed before it mattered.

All seven findings were remediated, and a focused retest of the authentication, session-management, authorization and time-entry workflows confirmed closure before additional tenants were onboarded to the platform.

For MSPs, IT firms and software agencies

Penetration testing for your clients, under your name or ours.

How partnering works

Common questions

The four we get asked first.

What does a penetration test cost?
Engagements start at $5,000 CAD. That is a real starting figure rather than a teaser, and it covers a focused assessment of a single application or a small external perimeter. Larger scopes cost more, and you get a fixed price in writing before any work begins.
What is included in the price?
Testing, the full written report, a walkthrough call to go through the findings with your developers, and one retest round of the reported findings within 60 days of the report. Nothing in that list is an upsell.
What is the retest?
Once you have remediated, we test the reported findings again and issue a retest summary confirming what is closed and what is still open. One retest round is included in every engagement, covering the findings in the report, within 60 days of the report being delivered. It is the only way to know a fix actually worked rather than appeared to.
How do we get started?
Request a scoping call. We will ask what you have built, what worries you, and what your constraints are, then propose a scope and a fixed price. Scoping calls are free and we do not require you to have answers ready.
All questions

Find out what an attacker would find first.