The Kind of Work We Do
Client engagements are confidential by default — that's part of what an NDA means. Rather than publish names or invented success metrics, here's an honest look at the type and shape of work we take on, with references available directly.
The examples below are illustrative composites describing typical engagement scope by industry — not a specific named client's real results.
Payment Platform — Web & API Assessment
A grey-box engagement covering the customer web application and the internal APIs handling transactions, scoped for PCI DSS Requirement 11.4. Testing focused on transaction-authorization boundaries between accounts and business-logic abuse in the payment flow.
B2B Platform — Multi-Tenant Isolation Testing
A web application penetration test with an explicit focus on whether one customer's tenant could access another's data, ahead of an enterprise customer's security review requirement.
Patient Portal — HIPAA-Aligned Testing
Testing of a patient-facing portal and its backend API, mapped to HIPAA Security Rule safeguards to support the client's annual risk analysis obligation.
Storefront & Admin Panel Assessment
A web application test covering the public storefront, checkout logic, and the internal admin/inventory panel, including a custom-built discount engine.
Internal Network & Active Directory Review
An internal network penetration test simulating a compromised employee laptop, mapping the path from initial foothold to domain admin.
Recurring Vulnerability Assessment Program
A quarterly vulnerability assessment program across a growing infrastructure estate, tracking new and recurring findings release over release.
Want to Talk to a Reference Directly?
With permission from the relevant client, we can put you in touch with a past client in a similar industry to yours instead of asking you to take our word for it.
Ready to Start Your Own Engagement?
Tell us what you'd like tested and we'll scope it properly.