Free website security check
An external security check of one business website, free of charge, with a report that is paid only when vulnerabilities are found. For businesses only.
Application security
Security testing for businesses · With the owner’s written permission
For businesses and professionals only. If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on how many there are and how serious they are. We test websites, applications, infrastructure, AI systems and smart contracts the way a real attacker would.
01Free check
For businesses. The check of your website costs nothing. If we find no vulnerabilities, the report is free of charge as well. The report is paid only when we find vulnerabilities, and its price depends on their number and severity.
And confirm that the website is yours. Before the check, the owner signs an authorisation with the address and the dates.
From the outside, the way an attacker sees it, in 1 to 5 business days after the authorisation is signed. Without destructive actions and without load tests.
No problems: a free report. Problems found: their number, their severity and the price of the report. The report comes immediately after payment; the retest after the fixes is free.
02Principles
Offensive security is a service only when it is authorised. These rules apply to every engagement and to every bug bounty report, without exceptions.
Testing starts after the asset owner has signed the authorisation and the scope. We verify that the signatory is entitled to sign.
We touch what is listed and nothing else. Systems of third parties are tested only with the consent of their operator.
On our bug bounty platform a program is published only after its owner has been verified, and every report is examined against the rules of the program.
A finding is reported once it has been reproduced. It carries proof, impact, a CVSS 4.0 vector and remediation steps.
We prove impact with the least intrusive action, stay away from production data and stop when a stop condition is met.
Findings belong to the client. Nothing is disclosed or published without written consent.
03Services
From a single web application to a full adversary simulation. Each service has a defined method, a defined deliverable and a price fixed before work starts.
An external security check of one business website, free of charge, with a report that is paid only when vulnerabilities are found. For businesses only.
Application security
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Application security
Testing of REST, GraphQL, gRPC and WebSocket interfaces for broken authorisation, data exposure and abuse of business flows.
Application security
Testing of iOS and Android applications together with their backend: storage, transport, platform interaction and resistance to tampering.
Application security
Manual review of source code, supported by static analysis, for vulnerabilities that cannot be seen from outside.
Application security
Assessment of AWS, Azure, Google Cloud and Kubernetes environments: identity, network exposure, data stores and paths from a foothold to full control.
Infrastructure and cloud
External and internal penetration testing of networks and Active Directory: from an exposed service or a single workstation to control of the domain.
Infrastructure and cloud
Discovery of everything your organisation exposes to the internet, known and forgotten, with each exposure verified by hand.
Infrastructure and cloud
Assessment of the path from a commit to production: repositories, pipelines, runners, dependencies and build artefacts.
Infrastructure and cloud
A goal-driven simulation of a real adversary against people, process and technology, to test whether an attack would be detected and stopped.
Adversary simulation
A joint exercise: we execute attack techniques one by one while your defenders tune detection and response.
Adversary simulation
Controlled phishing, phone and messaging campaigns that measure how people and processes respond, with results by group and never by name.
Adversary simulation
Adversarial testing of LLM applications, agents and MCP integrations: prompt injection, data leakage, tool abuse and escape from the intended task.
AI, Web3 and cryptography
Line-by-line audit of smart contracts and protocol logic before deployment: manual review, invariant testing and review of the fixes.
AI, Web3 and cryptography
Review of cryptographic design and implementation: protocols, key management, signatures and the generation of random values.
AI, Web3 and cryptography
Design, launch and operation of your bug bounty program: policy, scope, reward table, triage and communication with researchers.
Programs and assurance
A public channel and a working process for vulnerability reports from outside: policy, security.txt, intake, triage and coordinated disclosure.
Programs and assurance
Testing of every significant change and a scheduled re-examination of the perimeter, instead of one report a year.
Programs and assurance
Penetration testing scoped and documented to serve as evidence for PCI DSS, SOC 2, ISO/IEC 27001, DORA and NIS2.
Programs and assurance
04Engagement
How a paid engagement goes. Each step ends with a document you keep.
You describe the systems and the goal. We reply within 1 business day.
We agree assets, exclusions, test windows, accounts and contacts. You receive a proposal with the methodology and a fixed price.
The NDA, the contract and the authorisation letter are signed. Testing policies of your hosting and cloud providers are checked.
Manual testing supported by tooling. Critical and high findings are reported within 24 hours of confirmation, not held back for the final report.
An executive summary for management, technical detail for engineers and a walkthrough call with both.
Once the fixes are deployed we retest every finding within 60 days of the report and issue an attestation letter.
05Deliverable
The report is the product. Every finding in it is reproduced once more from its evidence before the report reaches you.
06Engagement models
The model follows the maturity of the system and the pace of its releases.
An external check of one website. You learn whether it is open to common attacks before you spend anything.
A defined set of assets is tested once, with a report and a retest.
We test every significant change and re-examine the perimeter on a schedule.
A private, time-boxed search for vulnerabilities carried out by us. You pay for confirmed vulnerabilities according to a reward table agreed in advance.
We design, launch and run your bug bounty or disclosure program: policy, scope, triage and communication with researchers.
07Bug bounty
Owners publish programs and name the reward. Researchers report vulnerabilities through us and are paid by us. We verify the owner, examine every report and answer for the money.
08Standards
We work to public standards, name the version and map findings to them. Following a standard is not the same as being certified against it: a certification is listed on this site only together with a link where it can be verified.
Test cases for web applications and APIs.
OWASP Foundation
Requirements an application is verified against.
OWASP Foundation
Test procedures for iOS and Android applications.
OWASP Foundation
The most critical risks of APIs.
OWASP Foundation
PTESv1.0
Phases of an engagement, from pre-engagement to reporting.
PTES Team
Planning, rules of engagement and conduct of technical testing.
NIST
Catalogue of adversary techniques used to plan operations and to report detection coverage.
The MITRE Corporation
Structure of threat-led red team tests: threat intelligence, red team phase, closure.
European Central Bank
The most critical risks of applications built on language models.
OWASP Gen AI Security Project
Catalogue of adversary techniques against AI systems.
The MITRE Corporation
Severity score and vector of every finding.
FIRST
Class of weakness behind every finding.
The MITRE Corporation
09Questions
Yes. The check itself costs nothing, and so does the report when no vulnerabilities are found. When we find vulnerabilities, you receive their number and severity free of charge and decide whether to buy the report; its price depends on the number and the severity of the findings.
Yes, when the owner of the system has authorised it in writing. Without authorisation the same actions are a criminal offence in most jurisdictions. That is why every engagement starts with an authorisation letter and a scope, and why we verify that the signatory has the authority to sign.
A penetration test is a time-boxed assessment by a contracted team against an agreed scope, with a report that covers everything tested. A bug bounty is an open-ended program in which independent researchers are rewarded for valid findings. The first gives assurance at a point in time, the second gives continuous discovery. Mature organisations use both.
The rules of engagement define what is allowed: test windows, request rates, excluded techniques and stop conditions. Denial-of-service testing is never performed unless you request it in writing. If we observe instability, we stop and call your contact.
By the size and complexity of the scope, the depth of testing and the access provided. After scoping you receive a fixed price; it does not change unless the scope does.
We collect the minimum evidence needed to prove a finding. Working data is stored encrypted and destroyed 30 days after the engagement is closed. Reports are delivered as encrypted archives by email, with the password sent separately by SMS or Signal.
Yes. The NDA is signed before you share any detail about your systems.
10Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.