How we work  /  Models surface the candidates. People prove the impact. Nothing ships unverified.
OFFENSIVE SECURITY

We build the models that find it.
We prove it by hand.

Our own models read your attack surface at a scale a team cannot — every endpoint, parameter and auth path. Then our testers take the candidates and establish what is actually exploitable. You get proven findings, not a scanner's queue.

Request scope & quote How we work

DISCOVERY AT SCALE

MODELS

Built in-house, tuned on real findings.

We develop our own models for surface mapping and vulnerability discovery, trained and refined against the classes we actually confirm in engagements — access control, tenant isolation, authentication logic.

COVERAGE

Every endpoint, not a sample.

Automated reasoning over the full surface — every route, parameter and role combination — so nothing is skipped because it looked uninteresting at 2am.

TRIAGE

A candidate is not a finding.

Model output is a lead. Every lead is adversarially tested, run against a negative control, and killed if it does not survive. Most do not. That is the point.

VARIANTS

One bug is a template.

When something is confirmed, we sweep the rest of your estate for the same pattern. Single findings are rarely single.

WHAT WE TEST

WEB & API

Authorisation, not just input validation.

Cross-tenant access, object-level and function-level authorisation, GraphQL resolvers, older API versions still mounted beside the current one.

MOBILE

The API contract behind the app.

Android and iOS clients, and the endpoints they reveal — usually a wider and older surface than the web application exposes.

CLOUD

Perimeter, identity, segmentation.

External exposure, cloud IAM, storage permissions, and whether network segmentation holds when you actually push on it.

COMPLIANCE

Scoped backwards from your audit date.

SOC 2, ISO 27001 and PCI DSS 11.4. Reported in the shape auditors accept — scope, methodology, severity, and documented retest of the fixes.

HOW WE WORK

01 / EVIDENCE

One command reproduces it.

Each finding ships with the exact request that triggers it and a control showing what a correct response looks like. Your engineer pastes it, sees it, fixes it, re-runs it. No "the application may be vulnerable to".

02 / TIMING

Findings as they are confirmed.

Not a PDF at the end. Remediation starts in week one, while we are still testing — which is also how the retest fits before your audit date.

03 / RETEST

Included, not a line item.

Verification of your fixes is part of the engagement. It is the evidence an auditor asks for, and charging separately for it has never made sense to us.

04 / SCOPE

What we could not reach, and why.

Stated plainly in the report. We would rather hand you a short honest list than pad it with informational findings nobody will action.

GET IN TOUCH

Send your stack, rough scope, and whether the test is tied to an audit date. You will get scope and a quote back, not a discovery call.

m.sherif@vigilsek.com