Security testing for businesses · With the owner’s written permission

Can your website be hacked? We check it free of charge.

For businesses and professionals only. If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on how many there are and how serious they are. We test websites, applications, infrastructure, AI systems and smart contracts the way a real attacker would.

01Free check

You pay only when we find a problem

For businesses. The check of your website costs nothing. If we find no vulnerabilities, the report is free of charge as well. The report is paid only when we find vulnerabilities, and its price depends on their number and severity.

  1. You send the address

    And confirm that the website is yours. Before the check, the owner signs an authorisation with the address and the dates.

  2. We check the website

    From the outside, the way an attacker sees it, in 1 to 5 business days after the authorisation is signed. Without destructive actions and without load tests.

  3. You receive the result

    No problems: a free report. Problems found: their number, their severity and the price of the report. The report comes immediately after payment; the retest after the fixes is free.

02Principles

Lawful by construction

Offensive security is a service only when it is authorised. These rules apply to every engagement and to every bug bounty report, without exceptions.

  • Written authorisation first

    Testing starts after the asset owner has signed the authorisation and the scope. We verify that the signatory is entitled to sign.

  • Scope is a boundary

    We touch what is listed and nothing else. Systems of third parties are tested only with the consent of their operator.

  • Verified programs only

    On our bug bounty platform a program is published only after its owner has been verified, and every report is examined against the rules of the program.

  • Evidence over opinion

    A finding is reported once it has been reproduced. It carries proof, impact, a CVSS 4.0 vector and remediation steps.

  • Minimal footprint

    We prove impact with the least intrusive action, stay away from production data and stop when a stop condition is met.

  • Confidential by default

    Findings belong to the client. Nothing is disclosed or published without written consent.

03Services

What we test

From a single web application to a full adversary simulation. Each service has a defined method, a defined deliverable and a price fixed before work starts.

  • Free website security check

    An external security check of one business website, free of charge, with a report that is paid only when vulnerabilities are found. For businesses only.

    Application security

  • API security testing

    Testing of REST, GraphQL, gRPC and WebSocket interfaces for broken authorisation, data exposure and abuse of business flows.

    Application security

  • Mobile application penetration testing

    Testing of iOS and Android applications together with their backend: storage, transport, platform interaction and resistance to tampering.

    Application security

  • Secure code review

    Manual review of source code, supported by static analysis, for vulnerabilities that cannot be seen from outside.

    Application security

  • Cloud & Kubernetes security assessment

    Assessment of AWS, Azure, Google Cloud and Kubernetes environments: identity, network exposure, data stores and paths from a foothold to full control.

    Infrastructure and cloud

  • Infrastructure penetration testing

    External and internal penetration testing of networks and Active Directory: from an exposed service or a single workstation to control of the domain.

    Infrastructure and cloud

  • External attack surface assessment

    Discovery of everything your organisation exposes to the internet, known and forgotten, with each exposure verified by hand.

    Infrastructure and cloud

  • CI/CD & supply chain security

    Assessment of the path from a commit to production: repositories, pipelines, runners, dependencies and build artefacts.

    Infrastructure and cloud

  • Red team operations

    A goal-driven simulation of a real adversary against people, process and technology, to test whether an attack would be detected and stopped.

    Adversary simulation

  • Purple team exercises

    A joint exercise: we execute attack techniques one by one while your defenders tune detection and response.

    Adversary simulation

  • Social engineering assessment

    Controlled phishing, phone and messaging campaigns that measure how people and processes respond, with results by group and never by name.

    Adversary simulation

  • AI & LLM security testing

    Adversarial testing of LLM applications, agents and MCP integrations: prompt injection, data leakage, tool abuse and escape from the intended task.

    AI, Web3 and cryptography

  • Smart contract audit

    Line-by-line audit of smart contracts and protocol logic before deployment: manual review, invariant testing and review of the fixes.

    AI, Web3 and cryptography

  • Cryptography review

    Review of cryptographic design and implementation: protocols, key management, signatures and the generation of random values.

    AI, Web3 and cryptography

  • Bug bounty program management

    Design, launch and operation of your bug bounty program: policy, scope, reward table, triage and communication with researchers.

    Programs and assurance

  • Vulnerability disclosure program (VDP)

    A public channel and a working process for vulnerability reports from outside: policy, security.txt, intake, triage and coordinated disclosure.

    Programs and assurance

  • Continuous penetration testing

    Testing of every significant change and a scheduled re-examination of the perimeter, instead of one report a year.

    Programs and assurance

04Engagement

From request to verified fix

How a paid engagement goes. Each step ends with a document you keep.

  1. Request

    You describe the systems and the goal. We reply within 1 business day.

    • Request reference
  2. Scoping

    We agree assets, exclusions, test windows, accounts and contacts. You receive a proposal with the methodology and a fixed price.

    • Proposal
  3. Authorisation

    The NDA, the contract and the authorisation letter are signed. Testing policies of your hosting and cloud providers are checked.

    • Authorisation letter, rules of engagement
  4. Testing

    Manual testing supported by tooling. Critical and high findings are reported within 24 hours of confirmation, not held back for the final report.

    • Urgent finding notices
  5. Report and debrief

    An executive summary for management, technical detail for engineers and a walkthrough call with both.

    • Report
  6. Retest

    Once the fixes are deployed we retest every finding within 60 days of the report and issue an attestation letter.

    • Retest report, attestation letter
See how we work

05Deliverable

A report written to be acted on

The report is the product. Every finding in it is reproduced once more from its evidence before the report reaches you.

Executive summary
Risk in business terms, the state of the system and the priorities, on two pages.
Scope and method
What was tested, when, from where, with which accounts, and what stayed out of scope.
Findings
One entry per issue: description, evidence, reproduction, impact, CVSS 4.0 vector, CWE, fix.
Attack paths
How separate weaknesses chain into a compromise, step by step.
Remediation plan
Fixes ordered by the risk they remove and the effort they take.
Retest results
The status of every finding after the fix, and the attestation letter.

06Engagement models

Ways to work with us

The model follows the maturity of the system and the pace of its releases.

  • Free website check

    An external check of one website. You learn whether it is open to common attacks before you spend anything.

    Fits
    A first look at the security of a public website.
    Pricing
    Free of charge. The report is paid only when vulnerabilities are found; its price depends on their number and severity.
  • Fixed-scope assessment

    A defined set of assets is tested once, with a report and a retest.

    Fits
    Releases, audits, due diligence, compliance deadlines.
    Pricing
    Fixed price for the agreed scope.
  • Continuous testing

    We test every significant change and re-examine the perimeter on a schedule.

    Fits
    Products that ship every week.
    Pricing
    Monthly fee for an agreed volume of testing.
  • Pay for results

    A private, time-boxed search for vulnerabilities carried out by us. You pay for confirmed vulnerabilities according to a reward table agreed in advance.

    Fits
    Mature systems that have been tested before.
    Pricing
    Reward per confirmed finding, with a budget cap.
  • Program management

    We design, launch and run your bug bounty or disclosure program: policy, scope, triage and communication with researchers.

    Fits
    Companies opening up to external researchers.
    Pricing
    Setup fee and a monthly management fee.

07Bug bounty

A platform where vulnerabilities are paid for under contract

Owners publish programs and name the reward. Researchers report vulnerabilities through us and are paid by us. We verify the owner, examine every report and answer for the money.

  • A program is published only after its owner has proved with documents that the system is theirs.
  • The owner sets the rewards. The researcher receives the whole reward.
  • Our commission is 20% of each reward and is paid by the owner. Amounts are stated without VAT; we are not registered for VAT and charge none.
  • Every report is examined, reproduced and rated on the CVSS 4.0 scale.
  • A report stays between the researcher, the owner and us.

08Standards

Methods you can look up

We work to public standards, name the version and map findings to them. Following a standard is not the same as being certified against it: a certification is listed on this site only together with a link where it can be verified.

Methodology

09Questions

Questions before a first engagement

Is the website check really free?

Yes. The check itself costs nothing, and so does the report when no vulnerabilities are found. When we find vulnerabilities, you receive their number and severity free of charge and decide whether to buy the report; its price depends on the number and the severity of the findings.

Is penetration testing legal?

Yes, when the owner of the system has authorised it in writing. Without authorisation the same actions are a criminal offence in most jurisdictions. That is why every engagement starts with an authorisation letter and a scope, and why we verify that the signatory has the authority to sign.

What is the difference between a penetration test and a bug bounty?

A penetration test is a time-boxed assessment by a contracted team against an agreed scope, with a report that covers everything tested. A bug bounty is an open-ended program in which independent researchers are rewarded for valid findings. The first gives assurance at a point in time, the second gives continuous discovery. Mature organisations use both.

Will testing disrupt production?

The rules of engagement define what is allowed: test windows, request rates, excluded techniques and stop conditions. Denial-of-service testing is never performed unless you request it in writing. If we observe instability, we stop and call your contact.

How is the price determined?

By the size and complexity of the scope, the depth of testing and the access provided. After scoping you receive a fixed price; it does not change unless the scope does.

What happens to our data?

We collect the minimum evidence needed to prove a finding. Working data is stored encrypted and destroyed 30 days after the engagement is closed. Reports are delivered as encrypted archives by email, with the password sent separately by SMS or Signal.

Do you sign an NDA?

Yes. The NDA is signed before you share any detail about your systems.

FAQ

10Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. We reply within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

For businesses. If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

We read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. We play a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

We and your defenders work side by side: we execute an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test scoped and documented to match what an auditor, a regulator or a large customer expects to see in a report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2. Whether the report is accepted is decided by them.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and we will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. Such material is exchanged later only as an encrypted archive, with the password sent separately.

Automated abuse check