HackproofHacks
Services

Test it before
someone else does

Five services, one approach: manual testing that asks how a skilled attacker would go after your application, and a report your engineers and your board can both act on.

NDA before anything starts / OWASP methodology / free debrief / retest included

What's on offer

Scoped around
your application

From a one-time penetration test to ongoing monitoring. Every engagement is shaped around your environment, your stack, and the risks that actually matter to your business.

01 Web Application Penetration Testing

Web Application Penetration Testing

A manual penetration test of your web application: authentication flows, authorisation controls, business logic, session management, and input handling. We use the OWASP Testing Guide as the baseline and go beyond it where your application warrants. The goal is practical: protect customer data and give you findings your team can fix this sprint.

Typical duration
3 to 10 business days depending on scope
Supports
PCI-DSS · ISO 27001 · SOC 2 · GDPR
Start this engagement

What you receive

  • Executive summary for non-technical stakeholders
  • Technical findings with CVSS scores and reproduction steps
  • Evidence screenshots and request/response captures
  • Prioritised remediation guidance per finding
  • Free 60-minute remediation debrief call
  • Free retest of critical and high findings

Scope coverage

  • Single-page applications (React, Vue, Angular)
  • Server-rendered web applications
  • E-commerce and payment flows
  • SaaS platforms and admin panels
  • Internal tools and intranets
02 API Security Testing

API Security Testing

Your API carries most of the risk in a modern application, and it is usually the least tested part. We test REST, GraphQL, and gRPC APIs against the OWASP API Top 10, with particular attention to object-level authorisation (BOLA), authentication weaknesses, mass assignment, rate limiting, and the business-logic flaws specific to your endpoints.

Typical duration
3 to 7 business days depending on scope
Supports
OWASP API Top 10 · ISO 27001 · SOC 2
Start this engagement

What you receive

  • Full API inventory mapping (including undocumented endpoints)
  • OWASP API Top 10 coverage with evidence
  • Authentication and authorisation test matrix
  • Rate limiting and resource consumption analysis
  • Remediation guidance per endpoint

Scope coverage

  • REST APIs (JSON, XML)
  • GraphQL APIs (including introspection)
  • gRPC services
  • Mobile app backends
  • Third-party API integrations
03 Vulnerability Assessment

Vulnerability Assessment

A structured assessment of your application and infrastructure to identify, classify, and prioritise known vulnerabilities. It is less intensive than a full penetration test, which makes it a good fit for a regular cadence between deeper engagements, or for establishing a baseline before your first pentest.

Typical duration
2 to 5 business days
Supports
ISO 27001 · SOC 2 · GDPR · NIST
Start this engagement

What you receive

  • Vulnerability inventory with severity ratings
  • CVSS-scored findings with patch guidance
  • Risk prioritisation matrix
  • Comparison against previous assessment (for recurring clients)
  • Written report and summary briefing

Scope coverage

  • Web applications and APIs
  • Cloud infrastructure (AWS, GCP, Azure)
  • Network and server configurations
  • Third-party component and dependency review
04 Security Monitoring

Security Monitoring

Ongoing security monitoring for your web application: automated scanning with human triage, monthly risk reports, and alerts when a newly disclosed CVE affects something in your stack. Useful for keeping assurance current between annual pentests, and for teams that ship fast enough that last quarter's assessment is already stale.

Typical duration
Ongoing monthly retainer
Supports
ISO 27001 · SOC 2 · GDPR
Start this engagement

What you receive

  • Monthly security report with new findings
  • CVE alerting for your technology stack
  • Remediation tracking across months
  • Quarterly trend analysis
  • Direct access to your assigned analyst

Scope coverage

  • Web applications and public-facing APIs
  • Dependency and third-party component tracking
  • New CVE monitoring for your stack
  • Configuration drift detection
05 Security Awareness Training

Security Awareness Training

Live security awareness sessions for developer and non-technical teams. Developer sessions cover secure coding fundamentals against the bugs we actually find in engagements; staff sessions cover phishing recognition, password practices, and social engineering. Content is tailored to your industry and threat model, and the sessions satisfy the training requirements in ISO 27001, SOC 2, GDPR, and HIPAA.

Typical duration
Half-day to full-day sessions; retainer available
Supports
ISO 27001 · SOC 2 · GDPR · HIPAA
Start this engagement

What you receive

  • Custom training curriculum for your organisation
  • Live interactive sessions (virtual or in-person)
  • Phishing simulation exercise
  • Post-training assessment
  • Actionable security policy recommendations

Scope coverage

  • Developer teams (secure coding fundamentals)
  • Non-technical staff (phishing, social engineering)
  • Management (security strategy and risk literacy)
  • DevOps and infrastructure teams
Method

How an engagement runs

A predictable process designed to work alongside your engineering team, from first contact to closed findings.

  1. 01

    Scoping call

    We define scope, objectives, rules of engagement, and timeline together. You get a firm quote before anything starts.

  2. 02

    Testing

    Manual testing following the agreed methodology, with an NDA in place from day one. Engagements longer than three days come with daily status updates.

  3. 03

    Report delivery

    Executive summary plus a full technical report with CVSS scores, evidence, and prioritised remediation. Delivered as PDF, or via a secure portal if you prefer.

  4. 04

    Debrief and retest

    A 60-minute call to walk your team through every finding. Critical and high findings are retested after remediation to confirm the fix holds.

Compliance

Evidence for
your auditors

Reports are structured so you can hand them straight to an auditor as compliance evidence. A compliance mapping document is available on request.

PCI-DSS

§11.4 mandates penetration testing

ISO 27001

Annex A.12.6 requires vulnerability management

SOC 2

CC6 addresses logical access and testing

GDPR

Art. 32 requires regular security testing

HIPAA

Security Rule §164.308 requires risk assessment

NIST CSF

Identify + Protect functions align with pentest

Clients

Who we work with

SaaS platforms

Customer data protection and multi-tenant isolation

Fintech and payments

PCI-DSS compliance and payment flow security

E-commerce

Checkout security and account takeover prevention

Healthtech

HIPAA alignment and patient data protection

Dev agencies

Pre-launch security reviews for client projects

Enterprise

Complex environments, compliance reporting, retainers

FAQ

Common questions

The questions CTOs, CISOs, and founders usually ask before a first engagement.

What is a web application penetration test?

A web application penetration test is an authorised, simulated attack against your application to identify security vulnerabilities before real attackers do. We use the same techniques as attackers, but with your explicit permission and within an agreed scope. You receive a detailed report with every finding, its severity, and step-by-step remediation guidance.

How long does a penetration test take?

Most web application penetration tests run 3 to 10 business days depending on the size and complexity of the scope. A single application with a moderate number of endpoints typically takes 5 days. We provide a scoping call before any engagement to give you an accurate estimate.

Do you follow a specific methodology?

Yes. We follow the OWASP Testing Guide and OWASP API Security Top 10 as our baseline methodology. Our testing combines automated scanning with extensive manual verification to catch business-logic vulnerabilities and chained attack paths that scanners miss entirely.

What do I receive at the end of a pentest?

You receive a comprehensive report covering: an executive summary suitable for non-technical stakeholders, a technical findings section with every vulnerability (severity, CVSS score, steps to reproduce, evidence screenshots), and a remediation guide with prioritised fix recommendations. We also offer a debrief call to walk through the findings with your engineering team.

Do you work with startups and SMEs, or only enterprise clients?

We work with businesses of all sizes, from early-stage startups preparing for a funding round to established SMEs and mid-market SaaS platforms. Engagements are scoped to your specific environment, not a one-size-fits-all package. We've worked with solo-founder products and 200-person engineering teams alike.

How much does a penetration test cost?

Pricing depends entirely on scope: the number of applications, endpoints, features, and testing objectives. A focused web application test for a mid-size SaaS typically starts at a few thousand dollars. We provide a firm quote after a free scoping call. There are no hidden extras: the quoted price includes the report, the debrief call, and a retest of critical findings.

Do you sign an NDA before starting?

Yes. We sign a mutual NDA and a formal Rules of Engagement document before any testing begins. No data collected during an engagement is retained after the report is delivered, and all testing is conducted under written authorisation. Your application details and findings are never shared with third parties.

Can you retest after we fix the vulnerabilities?

Yes. Every engagement includes a free retest of critical and high findings after remediation. This confirms the fix is effective and not bypassable. Additional retests for medium and low findings are available at a reduced rate for existing clients.

Will penetration testing disrupt our live environment?

No, not if scoped properly. We agree on testing windows before the engagement begins, typically avoiding peak business hours. For production environments, we can limit impact-heavy tests or run them against a staging environment. Most findings are identified through careful manual analysis, not disruptive exploitation.

Can a penetration test help us meet PCI-DSS, ISO 27001, or SOC 2 requirements?

Yes. Penetration testing is a mandated or strongly recommended control in PCI-DSS 11.4, ISO 27001 Annex A.12.6, SOC 2 CC6, and GDPR Article 32. Our reports are structured to support compliance evidence requirements, and we can provide a compliance mapping document on request to simplify your audit process.

What access or credentials do we need to provide?

It depends on the testing type. For black-box testing, you provide the target URL and written authorisation. For grey-box (most common for web apps), we need test accounts at different privilege levels. For white-box, we may request API documentation or architecture diagrams. We confirm requirements on the scoping call. Nothing starts until both parties agree to the scope in writing.

Who from our team should be involved in the engagement?

Typically a technical point of contact (lead engineer or DevOps lead) for day-to-day coordination, and a business stakeholder (CTO, CISO, or founder) for the scoping call and report debrief. We adapt to your team structure. Some clients also include their compliance officer or legal team at kickoff.

Start with a free scoping call

Tell us about your application, your stack, and what worries you. We'll help you understand your risk and recommend the right engagement. No commitment required, and you'll hear back within one business day.