Cybersecurity
We test websites, applications and bots the way an attacker would—only with your permission, and with a report instead of a breach. Every finding comes with reproduction steps and an assessment of what it means for the business.
Scope of work
point by point.
- Reconnaissance: subdomains, forgotten environments, open ports
- OWASP Top 10 checked by hand as well as by scanner
- Authentication, sessions, password recovery
- Access rights: horizontal and vertical privilege bypasses
- Injection: SQL, NoSQL, commands, templates
- File upload, XSS, SSRF, unsafe redirects
- Secrets in the repository, the bundle and the headers
- Vulnerable dependencies and outdated libraries
- Testing of Telegram bots and mobile APIs
- Report with priorities, proof of concept and a remediation plan
- Free retest after you have made the fixes
Situations
where this pays for itself.
Before launch
Testing before users ever see the product. Fixing it on a staging environment is cheaper than explaining an incident afterwards.
Report in 5–7 working days
A partner or bank requires it
A formal test report of the kind accepted in procurement and when applying for card acquiring.
Report in a compliance-ready format
After a breach
We look for the way in, close it and check that nothing has been left behind.
First findings within 24 hours
Audit of inherited code
The project came from a previous contractor with no documentation. We work out what is in there and where it is dangerous.
Risk map by component
Four steps
from brief to handover.
- 01
Scope and permission
We put in writing what is being tested and what must not be touched, then sign an NDA and a testing authorisation.
- 02
Reconnaissance
We build the map: subdomains, entry points, the stack, forgotten test environments.
- 03
Exploitation
We test the hypotheses. Critical findings are sent to you straight away, without waiting for the work to end.
- 04
Report and retest
You get the report with priorities. Once you have made the fixes, we check free of charge that the hole really is closed.
What we
build it with.
Three tiers.
The exact estimate follows the brief.
from ₽120,000
5–7 working days
- One site or bot
- OWASP Top 10
- Dependency and secret checks
- Report with priorities and proof of concept
- One free retest
from ₽350,000
10–20 working days
- Web, API and mobile clients
- Access rights checked role by role
- Source code review of the critical modules
- Infrastructure and CI/CD checks
- Walkthrough of the report with your team
on request
20–45 working days
- Several systems and the internal perimeter
- Social engineering scenarios, subject to agreement
- Threat model and risk map
- Secure development requirements
- Repeat audit six months later
Prices are the lower bound. What pushes an estimate up is set out on the pricing page
About this
service.
01How is this different from an automated scanner?
A scanner finds known patterns and reliably misses logic flaws: reaching someone else’s order through a direct link, a discount that can be applied twice, a payment cancelled after the goods have gone out. We run scanners as the first step and spend the bulk of the time checking the logic by hand.
02Can you break something?
On a production environment we work only by agreement and without destructive tests. The best option is to give us a copy on a separate environment—then we can test properly and risk nothing. The boundaries are agreed in writing before we start.
03What do we get at the end?
A report: a list of findings with a CVSS severity rating, reproduction steps, screenshots and a specific recommendation—which piece of code or which setting to change. Plus a one-page summary for management, with no jargon.
04Can you fix everything yourselves?
We can, but that is separate work. We deliberately keep the audit and the fixing apart: an auditor who patches their own findings stops being independent. If you do the fixing, we will help with the priorities and check the result free of charge.
Often taken
together with this one.
Get an estimate:
Cybersecurity
The brief takes 5–7 minutes. In working hours we reply within two hours, and the estimate is free.