Offensive testing

VAPT

Vulnerability assessment and penetration testing across your whole external estate rather than one application. We enumerate what you actually expose, run authenticated and unauthenticated assessment across it, then take everything the tooling flagged and prove by hand which findings are real. You get an ordered remediation list instead of a scanner export.

At a glance

Timeline

Three to five weeks for a typical estate: a week to scope and discover, two to three weeks of assessment and manual verification, and the report within three business days of the last test day.

You get

  • An inventory of everything you expose, whether or not it was vulnerable
  • Written report — executive summary plus per-finding technical detail
  • Reproduction steps and evidence for every verified finding
Who needs this

If any of these is your week, this is the service.

You do not have a current inventory of what you expose

Hosts have accumulated over years — old marketing sites, a staging box someone left public, a forgotten subdomain pointing at a dead bucket.

What we do

Discovery comes first: we enumerate the estate and hand you the inventory as a deliverable, whether or not anything on it turns out to be vulnerable.

A scanner gave you 400 findings and no priority

You have an automated report nobody can action, because it cannot tell an exploitable flaw from a version banner it does not like.

What we do

We validate every finding by hand, discard what is noise, and rank what survives by real business impact rather than CVSS alone.

An annual test is a contractual or regulatory obligation

A customer contract, an insurer or a regulator requires periodic third-party testing across the environment, on a documented cadence.

What we do

A repeatable annual or half-yearly engagement with a consistent scope, so each report is comparable to the last one.

How it works

Every step, and what leaves our hands at the end of it.

  1. 01

    Scope & authorise

    We agree the ranges, domains and environments in writing, name the prohibited techniques, and fix the testing window. Nothing is left to assumption.

    → Signed scope & authorisation

  2. 02

    Discover

    Enumerate the live estate: subdomains, hosts, open services, technologies and anything exposed that nobody meant to expose.

    → Asset inventory

  3. 03

    Assess

    Authenticated and unauthenticated assessment across the inventory, covering configuration, patch level, exposed services and access control.

  4. 04

    Verify by hand

    Every candidate finding is reproduced manually. What cannot be reproduced does not reach your report.

    → Verified findings with evidence

  5. 05

    Report & walk through

    A written report, then a live session with your engineers so the fixes are understood rather than filed.

    → Full report + remediation plan

  6. 06

    Retest

    Once you have shipped fixes we re-run every finding and reissue the report with each one marked closed.

    → Retest addendum

What you get

Deliverables.

  • An inventory of everything you expose, whether or not it was vulnerable
  • Written report — executive summary plus per-finding technical detail
  • Reproduction steps and evidence for every verified finding
  • Severity, business impact and a recommended fix per finding
  • An ordered remediation plan your team can work top-down
  • One free retest within 90 days, with a reissued report
What we need

Before we can quote.

  • 01The IP ranges and domains you own, as far as you know them
  • 02Credentials for any application you want tested authenticated
  • 03Anything we must not touch, and any maintenance window to avoid
  • 04A named technical contact who can answer questions during the window
  • 05Whether you need an attestation letter, and who it is addressed to

Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.

Questions

VAPT, answered.

How is VAPT different from a pentest?

Breadth against depth. VAPT covers the whole estate and verifies what assessment surfaces; a pentest goes deep on one application and chases business logic a broad sweep would never reach. Most teams start with VAPT to find out what they have, then pentest whatever turns out to matter.

Will this take anything down?

No. Denial-of-service is excluded entirely, we agree rate limits and a window before we start, and destructive checks run against staging or not at all. Production is tested only with your written consent.

What if we do not know what we own?

That is common, and it is the point of the discovery phase. Give us the domains and ranges you are confident about; the inventory we hand back is frequently the most useful part of the engagement.

Next step

Scope a VAPT.

VAPT is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.

Scope a VAPT1 business day

By submitting you agree to be contacted about your enquiry. We never share your details.