Skip to content
../services/security

ARSENAL 01

Security audit & pentest

Know where your weaknesses are before somebody else finds them.

We simulate the attacks a real adversary would attempt on your web applications, your APIs and your exposed infrastructure. You leave with a list of findings ranked by business risk, a demonstration of each one and the recommended fix. A retest is included: an audit that never verifies the fixes only produces a document.

Who it is for

  • Companies with a web application or API exposed to the internet
  • Organisations whose client or insurer is demanding a test attestation
  • Teams who just shipped a rebuild and want validation before opening it up
  • Any company that has never had its infrastructure tested

What you live with today

  • You have no idea whether your application would withstand a serious attempt
  • Your last audit predates three rebuilds and two changes of vendor
  • An important client requires a test report you do not have
  • An automated scanner produced two hundred alerts without saying which ones matter

What it gets you

Demonstrated

Every finding

We do not report a theoretical risk: each vulnerability comes with how it was actually exploited.

Prioritised

Remediation

Ranking is by impact on your business, not by technical score. You know what to fix on Monday morning.

Included

Retest

After your fixes, we re-verify the identified findings and update the report.

What is included

  • Web application testing guided by the OWASP risk categories
  • API testing: authentication, authorisation, data exposure
  • Attack-surface analysis: open services, forgotten subdomains, certificates
  • Source code review on sensitive areas when you grant access
  • A two-part report: executive summary and technical detail for your teams
  • Retest of the fixes and a dated attestation

How it runs

01

Scoping and written authorisation

1 week

We define the exact scope, testing hours and forbidden actions. Written authorisation is mandatory: without it, there is no test.

02

Testing phase

1 to 3 weeks

Reconnaissance, controlled exploitation and evidence gathering. Any critical finding is reported to you immediately, without waiting for the report.

03

Debrief

1 week

Report delivery and a walkthrough with your technical teams, so the fixes are understood rather than merely listed.

04

Retest

After your fixes

We re-verify each addressed finding and update the report and attestation.

Indicative timelines, depending on the number of applications, the depth required and environment availability.

The questions you are asking

Do you test production or staging?

Both are defensible. Staging removes any risk of disruption, but it often differs from production and can therefore hide real weaknesses. We discuss it during scoping and document the choice.

Can the test break something?

The risk is never zero, and we would rather say so. We reduce it with agreed testing windows, a list of forbidden actions and a direct contact channel throughout.

What is the difference between an audit and a pentest?

An audit examines your configuration, code and procedures — the inside view. A pentest tries to get in — the attacker’s view. They complement each other, and we often recommend starting with the audit when nothing has ever been done.

What happens to the vulnerabilities you find?

They stay confidential and belong to you. We can support the remediation, or hand the report to your team or your current vendor.

Better to discover your weaknesses yourself.

We define a scope proportionate to your real exposure, then test within a written, agreed framework.

The rest of the arsenal