/// Authorised Security Testing
Security Scan
& Pentest
An authorised penetration test of your web application, driven by an autonomous AI pentester running in an isolated sandbox. It probes the same weaknesses a real attacker would look for, then a human reviews every finding before it reaches you. We only ever run a test with your signed written permission and a scope you define.
What we test
Access control
IDOR, broken object-level checks, and authorisation bypass. Can one user reach another user's data or actions?
Injection
SQL and command injection. Where untrusted input reaches a database query or the operating system.
SSRF & XXE
Server-side request forgery and XML external entity flaws that make your server fetch or read things it should not.
XSS & client-side
Stored, reflected, and DOM-based cross-site scripting, plus client-side logic that can be turned against your users.
Business-logic flaws
Abuse of the way your app is meant to work: price tampering, skipped steps, replay, and quota or workflow bypass.
Auth & session
Login, password reset, multi-factor gaps, session handling, and JWT issues such as weak signing or token confusion.
Infrastructure misconfig
Exposed admin panels, default credentials, verbose errors, missing security headers, and leaking server config.
File & upload handling
Unrestricted upload, path traversal, and unsafe file processing that an attacker can use to plant or read files.
/// Read this first
How authorisation works
Penetration testing without permission is a crime. We test only systems you own or are clearly authorised to test, and we put that agreement in writing before anything starts. This keeps you on the right side of the UK Computer Misuse Act and keeps the whole engagement clean and accountable.
Signed written authorisation
You sign a document that names the exact systems in scope and confirms you have the right to authorise the test. No signature, no test.
Defined scope and window
We agree the precise targets, what is off-limits, and a fixed testing window. Nothing outside that scope is ever touched.
Isolated sandbox
The AI pentester runs in an isolated sandbox aimed only at your agreed targets. It cannot wander onto other systems.
Computer Misuse Act compliance
Because access is authorised by the system owner in writing and kept within scope, the work stays lawful under UK law.
If you do not own the target, or cannot show you are authorised to test it, we will not run the scan. There are no exceptions to this.
What you get
Findings report
A clear write-up of every confirmed issue, grouped by area, with enough context for your developers to act on it.
Validated proof of concept
Each finding comes with the exact steps to reproduce it, so there is no guesswork and nothing to argue about.
Severity ratings
Every issue is rated by real-world impact and likelihood, so you can see at a glance what actually matters.
Prioritised remediation
Specific, ordered fixes. What to patch first, what can wait, and how to close each gap for good.
Human review pass
A security engineer checks every result by hand. You get verified findings, not raw tool output or false positives.
Debrief on request
Want to talk it through? We will walk your team through the report and answer questions on the fixes.
Tell us your target and scope. We confirm fit before any work begins.