Offensive security, ongoing
We test what you've already put into production (application, infrastructure, and AI agents) before someone outside does.
Request a diagnosticThe problem
A production system that's never been security-tested can carry unknown risk until the day someone exploits it. Finding out through an incident tends to be the most expensive way to find out.
What's included
- A scope fixed in writing before any testing begins
- A technical report with severity ratings and reproduction steps
- A retest after fixes ship
- A direct line to whoever ran the test, not an anonymous report
- An LGPD-aligned process when testing turns up exposed personal data
Packages
- Web application penetration testManual testing of a web application against a defined scope of domains and IPs.Testing window set in the signed scope, after written authorization
- Post-fix retestA second pass to verify reported findings were actually fixed.Scheduled once fixes are reported ready
- Managed bug bountyOngoing vulnerability hunting within the agreed scope, findings triaged by severity.Ongoing, with a periodic report
- AI Red TeamingTesting for prompt injection, context leakage, and connected-tool abuse in AI agents.Testing window set in the signed scope, after written authorization
How it works
Scope and authorization
Domains, IPs, and the testing window defined and signed off in writing before any activity.
Testing
Execution within the agreed scope, never beyond what was authorized.
Report
Findings with severity, evidence, and reproduction steps.
Retest
Verifying the fix actually closed the reported issue.
Frequently asked questions
Do I need to authorize this in writing even though it's my own system?
Yes. That's what separates a legitimate test from unauthorized access, and the authorization protects both sides.
Can testing bring down our production system?
The scope and testing window are agreed on exactly to reduce that risk, and critical systems can be tested outside peak hours.
Do you test just the application, or the infrastructure too?
It depends on the agreed scope. The domains, IPs, and layers tested are spelled out in the authorization document.
What happens if you find exposed personal data?
We follow an LGPD-aligned process, reported to you separately from the general technical report.
How much does a penetration test cost?
We don't publish fixed prices. The cost depends on scope and attack surface, and we quote in writing after understanding what needs testing.
Scope and authorization
Every security engagement we run starts with written authorization, a delimited scope (explicit domains and IPs), and a testing window agreed with you in advance. That's what makes the test legitimate, and it means both sides know exactly what's being tested, when, and within what limits.
- Written authorization before any testing activity
- A delimited scope, with explicit domains and IPs
- A testing window agreed in advance
Let's talk about your security test
Tell us what needs testing. We've preselected Security in the form.
Request a diagnostic