VAPT
Vulnerability assessment and penetration testing across your whole external estate rather than one application. We enumerate what you actually expose, run authenticated and unauthenticated assessment across it, then take everything the tooling flagged and prove by hand which findings are real. You get an ordered remediation list instead of a scanner export.
Timeline
Three to five weeks for a typical estate: a week to scope and discover, two to three weeks of assessment and manual verification, and the report within three business days of the last test day.
You get
- An inventory of everything you expose, whether or not it was vulnerable
- Written report — executive summary plus per-finding technical detail
- Reproduction steps and evidence for every verified finding
If any of these is your week, this is the service.
You do not have a current inventory of what you expose
Hosts have accumulated over years — old marketing sites, a staging box someone left public, a forgotten subdomain pointing at a dead bucket.
What we do
Discovery comes first: we enumerate the estate and hand you the inventory as a deliverable, whether or not anything on it turns out to be vulnerable.
A scanner gave you 400 findings and no priority
You have an automated report nobody can action, because it cannot tell an exploitable flaw from a version banner it does not like.
What we do
We validate every finding by hand, discard what is noise, and rank what survives by real business impact rather than CVSS alone.
An annual test is a contractual or regulatory obligation
A customer contract, an insurer or a regulator requires periodic third-party testing across the environment, on a documented cadence.
What we do
A repeatable annual or half-yearly engagement with a consistent scope, so each report is comparable to the last one.
Every step, and what leaves our hands at the end of it.
- 01
Scope & authorise
We agree the ranges, domains and environments in writing, name the prohibited techniques, and fix the testing window. Nothing is left to assumption.
→ Signed scope & authorisation
- 02
Discover
Enumerate the live estate: subdomains, hosts, open services, technologies and anything exposed that nobody meant to expose.
→ Asset inventory
- 03
Assess
Authenticated and unauthenticated assessment across the inventory, covering configuration, patch level, exposed services and access control.
- 04
Verify by hand
Every candidate finding is reproduced manually. What cannot be reproduced does not reach your report.
→ Verified findings with evidence
- 05
Report & walk through
A written report, then a live session with your engineers so the fixes are understood rather than filed.
→ Full report + remediation plan
- 06
Retest
Once you have shipped fixes we re-run every finding and reissue the report with each one marked closed.
→ Retest addendum
Deliverables.
- An inventory of everything you expose, whether or not it was vulnerable
- Written report — executive summary plus per-finding technical detail
- Reproduction steps and evidence for every verified finding
- Severity, business impact and a recommended fix per finding
- An ordered remediation plan your team can work top-down
- One free retest within 90 days, with a reissued report
Before we can quote.
- 01The IP ranges and domains you own, as far as you know them
- 02Credentials for any application you want tested authenticated
- 03Anything we must not touch, and any maintenance window to avoid
- 04A named technical contact who can answer questions during the window
- 05Whether you need an attestation letter, and who it is addressed to
Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.
VAPT, answered.
How is VAPT different from a pentest?
Breadth against depth. VAPT covers the whole estate and verifies what assessment surfaces; a pentest goes deep on one application and chases business logic a broad sweep would never reach. Most teams start with VAPT to find out what they have, then pentest whatever turns out to matter.
Will this take anything down?
No. Denial-of-service is excluded entirely, we agree rate limits and a window before we start, and destructive checks run against staging or not at all. Production is tested only with your written consent.
What if we do not know what we own?
That is common, and it is the point of the discovery phase. Give us the domains and ranges you are confident about; the inventory we hand back is frequently the most useful part of the engagement.
Scope a VAPT.
VAPT is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.