~/servicesServices

Offensive Security, And The Readiness Work Behind Compliance.

Two things we do. We break product logic and prove it, across every surface a product exposes. And we run the readiness work behind the frameworks your customers ask about, so you walk into the formal assessment already prepared.

Offensive security

Manual penetration testing and code audits. Every finding ships with a working proof of exploit and a retest included.

12 services
  1. Web penetration testing

    Manual testing of authenticated application logic, not a scanner run.

    5 to 12 working days
  2. API penetration testing

    REST, GraphQL and internal service APIs, tested against real auth flows.

    4 to 10 working days
  3. Network penetration testing

    External perimeter and internal network assessment.

    5 to 10 working days
  4. Phishing simulation

    Controlled phishing against your own staff, run under written authorization.

    2 to 4 weeks
  5. Dark web monitoring & threat intelligence

    Continuous watch for your credentials, data and brand outside your perimeter.

    Ongoing, monthly reporting
  6. Red teaming

    Objective-based, multi-vector adversary simulation.

    3 to 6 weeks
  7. Source code review

    Manual review of the code paths that carry security decisions.

    5 to 12 working days
  8. AI / LLM penetration testing

    Security testing of LLM applications, agents and their tool access.

    5 to 10 working days
  9. Mobile application testing

    Android (APK) and iOS clients, plus the APIs behind them.

    5 to 10 working days
  10. Thick client application testing

    Desktop applications and the services behind them.

    5 to 12 working days
  11. Cloud security review

    AWS, Azure and Google Cloud identity and configuration review.

    5 to 12 working days
  12. Blockchain & smart contract audit

    Solidity and protocol-level review of on-chain logic.

    1 to 4 weeks
Compliance and readiness

Readiness assessments against the frameworks below. We run the gap analysis and the pre-assessment work, and write the evidence your auditor needs. We do not issue certificates: certification comes from an accredited body or a licensed CPA firm, and we work alongside whoever you choose.

10 frameworks
  1. PCI DSS readiness

    Payment Card Industry Data Security Standard readiness and gap assessment.

    Readiness
  2. ISO/IEC 27001 readiness

    ISO/IEC 27001:2022 information security management readiness.

    Readiness
  3. ISO/IEC 42001 readiness

    ISO/IEC 42001:2023 AI management system readiness.

    Readiness
  4. ISO/IEC 27701 (PIMS) readiness

    Privacy Information Management System (PIMS) readiness against ISO/IEC 27701:2025.

    Readiness
  5. SOC 2 Type 1 readiness

    System and Organization Controls 2, Type 1 (controls as designed, on a single date) readiness.

    Readiness
  6. SOC 2 Type 2 readiness

    System and Organization Controls 2, Type 2 (controls operating across a period) readiness.

    Readiness
  7. HITRUST readiness

    HITRUST CSF (Health Information Trust Alliance) readiness assessment.

    Readiness
  8. HIPAA readiness

    Health Insurance Portability and Accountability Act security and privacy review.

    Readiness
  9. GDPR readiness

    General Data Protection Regulation compliance and data-handling review.

    Readiness
  10. India DPDP Act readiness

    Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 readiness.

    Readiness

Prove what your product exposes

A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.