Your organisation has vulnerabilities you don't know about. Attackers will find them anyway, whether through technology, deception, or the unlocked door to your server room. We find them first: with tailored penetration tests, clear recommendations, and a focus on physical pentesting, social engineering & OT/ICS.
From physical security to Active Directory – every module can be booked individually or combined into a comprehensive security assessment.
A chained campaign, not a single module: recon, phishing, physical access, and Active Directory combined toward one defined objective, covert and objective-based.
Learn more
We assess the physical security of your company locations – from access control to locks and alarm systems. Through simulated break-in attempts, we uncover vulnerabilities before real attackers do.
Learn more
Technology is only as strong as the people operating it. We test your organisation with targeted deception attempts – such as phishing, vishing, or personal contact – and show how resilient your security culture really is.
Learn more
We systematically analyse your internal or external IT infrastructure for vulnerabilities. This includes networks, servers, firewalls, and more – comprehensively, securely, and fully documented.
Learn more
Web applications are common targets – we thoroughly test your apps for security flaws like XSS, SQL injection, or access control weaknesses. Our approach follows established standards such as OWASP Top 10.
Learn more
You often reveal more about yourself than you think. We use publicly available information to build a realistic attack profile – showing you what potential attackers already know about you.
Learn more
We analyse your Windows domain structure with a focus on permissions, group policies, and possible privilege escalations. The goal is to uncover typical attack paths in AD environments before they can be exploited.
Learn more
AI systems are increasingly integrated into business processes, but they also introduce new attack vectors. We test your AI applications for vulnerabilities such as prompt injection, data leakage, or model manipulation – ensuring your AI is secure against emerging threats.
Learn more
Industrial control systems and OT networks are increasingly connected – and increasingly at risk. We assess your SCADA systems, PLCs and OT infrastructure for vulnerabilities without disrupting ongoing operations.
Learn more
Nothing suitable here? No problem – we offer tailored security analyses to meet your specific requirements. Whether specialised technologies, hybrid environments, or unusual scenarios: we develop a custom testing concept that fits your organisation perfectly.
Every module above tests a single point in time. Continuous tests every month, automated and with real exploits. And once a month your pentester goes through the results with you.
Before we attack your systems, we proved we could: our pentesters hold recognized offensive security certifications like OSCP, CRTO, and CRTP - hands-on exams that demand real hacking skill, not multiple-choice knowledge.
We sell no firewalls, no licences, no managed services. Whoever finds vulnerabilities and sells the fix at the same time has a conflict of interest. We do not – our findings are independent.
Many test networks and web apps. Our focus is where few look: at the factory gate, the reception desk, your employees' inboxes and your production control systems.
No catalogue package, no flat rate per IP. Scope, approach and offer are derived from your infrastructure, your threat profile and your budget – and nothing else.
Even a classic infrastructure or Active Directory pentest can take place at your premises: short paths to your IT, questions answered in conversation rather than by ticket – across the DACH region and Europe.
Offer, findings, questions, files, report: everything in one portal you use from day one. Critical findings appear as soon as we record them.
After every pentest you receive a certificate with a reference code. Insurers, customers and auditors verify its authenticity online – without asking you.
Florian Schüssler reconstructed real attacks as a cybercrime investigator with the criminal police before simulating them himself as a penetration tester and red teamer. Today he teaches IT security at DHBW – and still tests at Access Granted himself. You talk to the person who runs the test.
Free initial consultation
In 30 minutes we discuss your scope, answer open questions and you receive a first proposal – no obligation, no cost.
More references and project examples available on request.
Request a referenceDuring an initial meeting, scope, goals, conditions, and technical details of the planned pentest are agreed upon.
No off-the-shelf package: based on the scoping we create an offer that fits your exact scope. You review it in the client portal, add or remove optional items and sign digitally – even from your phone.
Contacts, schedule and technical prerequisites are agreed. Credentials are exchanged encrypted via the portal, and you sign the test authorisation there digitally.
Execution follows the agreed scope – on your premises where it helps the result – considering the defined systems, scenarios and any agreed limitations.
Critical findings are reported immediately, not just in the report. In the client portal you see findings as they come in, ask the tester directly and follow the operational log of what was tested when.
After the test we prepare a detailed report, available as a PDF in the client portal. Optionally, results are presented in a closing meeting.
After every pentest we issue a certificate with a unique reference code. Insurers, customers or auditors verify its authenticity in seconds at access-granted.de/verify.
Offer, report, certificate, files and history remain available in the client portal – for the next audit, the re-test or a request from management, your cyber insurer or a customer.
What you end up holding
No email ping-pong, no Excel list of findings: every customer gets access to app.access-granted.de – from the first offer to the certificate.
Cyber insurers, corporate customers and auditors increasingly ask for proof of completed pentests. Our certificate carries a reference code that any third party can verify online – without asking us or you.
Made for cyber insurers, customers and supply chain, auditors and management.
Verify a certificateOur automated Quick Check reviews subdomains, email security, exposed services, certificates, and typosquatting - in minutes, no obligation.
30 minutes, free & no obligation.
We respond within 24 hours.
Direct by email
hello@access-granted.deNo automated replies. Your enquiry goes directly to the team.