Not every environment fits a ready-made package. Tell us what worries you, and we tailor the scope to it. You talk to the testers, not to sales.
A pentest starts with a clear question, not with a product name. We fill in these four fields together in the scoping call. What is on the right is what we make of it.
What exists and what has changed
We have our own Android app with a backend, and a customer is asking for proof.
What to protect against
Can someone use the app to get at other users' data?
Systems, limits, depth
App and backend interfaces according to OWASP MASVS, grey box with a test account, no load tests.
What you have in hand at the end
Report with findings mapped to the MASVS categories, plus a retest.
How much we know up front changes both the insight and the effort. Often it is a combination.
No prior knowledge, like an attacker on the internet. Realistic, but slower.
Partial information like a test account or network sketch. Good middle ground.
Full insight including source code and architecture. Finds the most per day.
Code review · Live hacking · Mobile app pentest · Password audit · Dark web analysis · Wi-Fi pentest · Incident response · Cloud and hybrid · OT, IoT and hardware · Air-gap and special lab · LLM and AI security · Product security · Vulnerability scan · Purple teaming · Workshops and awareness
This is a selection, not a fixed catalogue. Topic missing? Ask for it. We will tell you honestly whether and how we can test it properly.
Our basis is the BSI penetration-testing methodology with its five phases, from preparation through to the final analysis. It also grades how aggressively a test may proceed: we point out weaknesses and exploit them only as far as is necessary to prove the risk. You can use the report as evidence for your internal audits and to meet requirements arising from ISO 27001, TISAX and NIS2.
We never request more access than the agreed test really needs.
Goals, systems and permitted attack depth, free of charge and without obligation.
Written fixed-price offer, plus the formal test authorisation.
Test in the agreed window, critical findings immediately, not only in the report.
Risk assessment, evidence and concrete measures, which you can use for audits.
Targeted check of whether the gaps are really closed.
Reading the source code instead of only testing from outside: finds logic and authorisation flaws that a black-box test never triggers. Requires read access to the repository.
Real attacks on prepared demo systems, demonstrated to staff, management or at a trade fair. As a talk or workshop, lasting 45 to 90 minutes.
Testing against OWASP MASVS v2.1 following the testing guide MASTG v2.0. Static analysis of the app package plus dynamic tests on the device.
NTLM hashes from Active Directory, tested offline with Hashcat against word lists and leak collections. Plaintext never leaves your premises.
Search for your domains, accounts and documents in infostealer logs, on leak sites and in combo lists. Purely passive, without buying illegal data.
On site, for WPA2 and WPA3. A common weak spot is clients that do not verify the RADIUS certificate and fall for an evil twin.
Support during an active incident according to NIST SP 800-61 Rev. 3, with the deadlines under section 32 BSIG in view: 24 hours for the initial report, 72 hours for the notification, one month for the final report.
Systems, attack depth and duration determine the price, which is why every engagement starts with a free scoping call. You then receive a written fixed-price offer, with no hidden costs and no call centre in between.
That is exactly what this route is for. Describe your topic to us, and we will tell you honestly whether and how we can test it in a meaningful way.
Tell us in a few sentences what is on your mind. You get an honest assessment and a clear next step.