Home/Services/Penetration testing

Penetration testing

Web applications, APIs, mobile apps and internal networks, tested by hand inside an agreed window. Every finding arrives with the steps to reproduce it, ranked in the order I would fix them.

What gets tested

Web applications

Authentication and session handling, access control between accounts and between roles, injection into whatever the application talks to, and the business logic that only makes sense once you understand what the application is for. The last category is the one scanners never find.

APIs

REST and GraphQL, including the endpoints that are not in the documentation. Object-level authorisation, mass assignment, missing rate limits, and what happens when a client sends a field it should not know about.

Mobile applications

Android and iOS. What the binary gives away, what the app stores on the device, what it accepts from other apps on the same phone, and whether the backend trusts the client more than it should.

Internal networks

What one foothold turns into. Credential reuse, service misconfiguration, and the path from an ordinary workstation to something that actually matters.

How it runs

  1. 01

    Scope

    A call, then a short written document: which systems, which accounts, which windows, and what is explicitly out of bounds. You get a fixed price before anything starts.

  2. 02

    Test

    Hands on keyboard inside the agreed window. Anything critical reaches you the same day it is found, with enough detail to start acting on before the report exists.

  3. 03

    Report

    Findings ranked by what I would fix first. Each one carries reproduction steps, the impact stated in terms of your systems rather than a generic severity label, and a concrete remedy.

  4. 04

    Retest

    Once the fixes land, I verify them and reissue the report. Included in the original price.

What you get

  • A written scope and a fixed price, agreed before the work starts.
  • Same-day notice for anything critical, rather than a surprise on page 40.
  • A report ordered by what to fix first, not by CVSS score alone.
  • Reproduction steps for every finding, written so your developers can trigger it themselves.
  • A remediation section aimed at the people who have to act on it.
  • A retest of the fixes and a reissued report, at no extra cost.

What this is not

  • Not a scanner export. Automated tools are part of the work. They are not the work.
  • Not a compliance certificate. If you need a specific attestation, raise it at scope time and I will tell you plainly whether this produces it.
  • Not a red team exercise. This is a scoped test against agreed systems, not an unannounced attempt to reach a goal by any available route.
  • Not continuous. A penetration test describes a window in time; attack surface monitoring is what covers the rest of the year.

Common questions

What do you need from us before you start?

A contact who can answer questions during the test, credentials for each role you want covered, and a written go-ahead from someone entitled to give it.

For anything hosted by a third party, check your contract first. Some providers require notice before testing.

Do you test with credentials or without?

Usually both. Testing without credentials shows what a stranger reaches. Testing with them shows what one compromised account turns into, which is almost always the larger number.

Unauthenticated-only testing is possible if that is genuinely your threat model, but it tends to buy less than it costs.

Could the test break something?

It can, which is why scope says which systems and which windows. Destructive checks are agreed in advance or not run at all.

If you have a staging environment that genuinely matches production, that is usually the better target. Where it does not match, testing it mostly proves things about staging.

How long does it take, and what does it cost?

Both come out of scoping, and both are fixed in writing before the work starts. Scope drives duration; duration drives price.

Will you sign an NDA?

Yes.

What happens if you find nothing serious?

You get the report anyway, including what was tested and found sound. That is the part that makes the result mean something — a report with no findings and no method behind it says nothing at all.

Start a conversation

Tell me what you are running,
and what worries you about it.

[email protected]

Replies within one working day. Dutch or English.