Skip to content
SERVICES

Choose your audit depth.

Three tiers — automated, hybrid, human-led — each mapped to the depth your regulator (NIS2 Article 21, DORA Articles 24–26, SEC 17 CFR §229.106, SOC 2 CC7.1) actually asks you to demonstrate. Pick by risk, not by catalogue.

01
CUSTOM AUDIT · AUTOMATED

Nuclei + Naabu + Subfinder against your public attack surface, TLS posture graded against RFC 9325, security-header sweep against the OWASP SHP baseline. Non-intrusive, CVSS 4.0-scored, delivered as a signed PDF. Right for the startup that needs a monthly point-in-time read on external exposure.

02
ADVANCED AUDIT · HYBRID

Automation from tier 1 plus one to two targeted manual tests against the areas machines cannot judge — authorisation-adjacent business logic, session integrity, and multi-tenant BOLA / BFLA. Report tuned to your framework of choice (SOC 2 CC7.1, ISO 27001 A.5.30). Right for the scale-up carrying a security review at a funding round.

03
EXPERT MANUAL AUDIT · GREY-BOX

Full engagement to PTES phases 1–7, OWASP WSTG v4.2, and OWASP ASVS Level 2, with MITRE ATT&CK v14 kill-chain mapping. Business-logic depth, session-integrity forensics, multi-role and multi-tenant authorisation, and a threat-led penetration testing dossier aligned with DORA Articles 24–26. Right for the enterprise whose incident timeline lands in an 8-K.

PRICING

See tier pricing and full inclusions.