Skip to main content

Penetration testing and security testing

Penetration testing of websites, APIs and systems. We find the security holes before attackers do, and you get a report with prioritised findings.

Security should be tested, not assumed. We carry out penetration testing — also called pentesting — and other security testing of systems we have written permission to test: websites, web applications, APIs and the configuration they run on. Scope is agreed before we start, and you are left with a report that says what is wrong, how serious it is and what should be fixed first.

Benefits

Proactive risk reduction before and after launch
Concrete findings with clear prioritisation
An independent external assessment of your cybersecurity
A safer launch and a better basis for decisions
Documentation you can show clients and partners
Actions you can follow up internally or together with us

Features

Reconnaissance and OSINT
Port scanning and service mapping
Analysis of JavaScript bundles
API endpoint testing
Authentication and access control testing
HTTP security headers and CSP review
A report with recommended actions

Our Process

Start

Scoping and clarification

We agree scope, goals and methodology with you. The test is carried out only against systems you own or have written permission to test.

Reconnaissance

We map exposed information, subdomains, technology stack and other attack vectors from an external perspective, the way a real attacker would.

Structured testing

We systematically test APIs, authentication, security headers, JavaScript bundles and configuration according to the agreed methodology.

Report

You get a classified report with every finding sorted by severity and impact, along with concrete recommendations for remediation.

Finish

Follow-up

We go through the report with you, answer questions and can assist with fixing the findings if you want.

Frequently asked questions

What does a penetration test involve, and what do you get out of it?

We attempt to break into the system the same ways a real attacker would. After the test we document every weakness we found, grade them by severity and give concrete recommendations for what should be fixed and in what order. You are left with a report that shows actual security risk, not just a list of theoretical vulnerabilities.

What does a penetration test cost?

As everywhere else with us, the price follows the scope — there is no standard package. Reviewing a single website is a very different job from a full test of a system with many integrations, and we size the work accordingly. We agree what is to be tested in a no-obligation conversation first, and you get scope and price in writing before the test starts.

What is the difference between security testing and an automated vulnerability scan?

A scanner works through known signatures and patterns without understanding the system it is looking at. Security testing takes professional judgement of the whole: how the system actually works, where the logic flaws are, which weaknesses can be combined, and what could realistically be exploited. Automated scanning is one of several steps in our work, but it is the assessment of the findings that decides what is genuinely a risk to you.

Ready to get started?

Let us talk about how we can help your business with penetration testing and security testing.

Based in Rogaland? Read about web development in Haugesund.