Web-app penetration testing
Black- and grey-box testing of your web application: authentication, business logic, injection and access-control flaws found and proven, with fixes ranked by real risk.

Find the way in. Close it before someone else opens it.
The same instinct that names a thought on stage finds the exposure a system gave away without meaning to: the that trusts the wrong input, the subdomain nobody decommissioned, the a login form makes. I attack it the way a real attacker would, then hand you exactly what to close, in plain language. Quietly.
Black- and grey-box testing of your web application: authentication, business logic, injection and access-control flaws found and proven, with fixes ranked by real risk.
Your APIs, sessions and access controls pushed the way an attacker would: broken object-level authorisation, token handling and privilege escalation, demonstrated end to end.
Findings written so the fix is obvious and prioritised by genuine impact. Then a retest once you've closed them, to prove the holes are gone.
Nothing about an engagement is discussed, named or referenced anywhere. The secure channel is the only channel.
Scoped, authorised and within the law, always. Written permission before a single packet. No exceptions, no grey areas.
Signal, not noise. Findings are reproducible, prioritised by genuine impact, and written so the fix is obvious.
You request a channel. We move off open email to something encrypted, and you share only the minimum to begin.
We agree targets, boundaries and timing in writing. Nothing happens outside the signed scope.
Recon, testing and verification, documented as I go, with anything critical flagged to you in real time.
A clear report: what was found, why it matters, and the exact steps to close it. A retest when you've fixed it.

Keep the detail out of this first message. We'll move to a secure channel before anything sensitive is shared.