Skip to content
Client access

Service

Penetration Testing

Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.

Automation
Kynapt, our continuous monitoring engine, discovers your exposed assets, identifies technologies and versions, and retests them whenever a vulnerability that affects them is published.
Human validation
Certified pentesters (OSCP, OSCP+, CRTP, eCPPT, eWPTX and more) manually exploit what Kynapt flags and look for what no tool can see. You follow progress in your portal.

The challenge

Find your vulnerabilities before an attacker does

An automated scanner can list hundreds of alerts, but it cannot tell which ones are exploitable, and it misses business logic flaws, broken access controls and combinations of weaknesses that together lead to a compromise.

In a penetration test, certified consultants try to exploit your systems manually and in a controlled way, just as an attacker would, and document the real impact of every finding.

The result is a prioritized list of what to fix, with the evidence your technical teams, auditors and regulators need.

What we assess

Every surface an attacker could come through

We scope the test to your risk: a critical application, a set of systems or your entire exposed surface.

Web applications

Authentication, session management, access control, injection flaws and business logic, following the OWASP WSTG.

APIs

REST and GraphQL APIs: object- and function-level authorization, data exposure and logic abuse, based on the OWASP API Security Top 10.

Mobile applications

Android and iOS apps: local storage, backend communication and anti-tampering protections, based on OWASP MASVS.

External and internal infrastructure

Internet-facing services, internal networks, servers and Active Directory, to identify the paths to a compromise.

Wireless networks

Wi-Fi configuration and encryption, guest networks, segmentation and rogue access points.

Cloud

Configurations, identities and services in AWS, Azure and Google Cloud: excessive permissions, exposed storage and escalation paths.

How we work

A proven methodology, always under control

01

Scope and authorization

We agree on objectives, systems, test type (black, gray or white box), testing windows and contacts, with formal authorization.

02

Reconnaissance

We gather information about the target surface and map technologies, entry points and functionality.

03

Vulnerability analysis

We combine automated tools with manual review to identify weaknesses and rule out false positives.

04

Controlled exploitation

We confirm the real impact of each finding without affecting the availability or integrity of your data.

05

Reporting and briefing

We document every finding with evidence, severity and recommendation, and present it to technical teams and leadership.

06

Retest

We verify that fixes for critical and high findings work and issue a closing report.

Deliverables

Prioritized findings, ready to fix

Reference frameworks

  • OWASP WSTG
  • OWASP API Top 10
  • OWASP MASVS
  • PTES
  • NIST SP 800-115
  • CVSS
  • Executive summaryRisk level, key findings and recommendations in business language.
  • Technical reportEvery finding with evidence, reproduction steps, CVSS severity and remediation guidance.
  • Remediation planFindings ranked by risk and effort to plan the fixes.
  • Results briefingA session with your teams to answer technical questions and agree on priorities.
  • Retest and closing reportVerification of the fixes and the final status of every finding.
  • Attestation letterA document certifying the test was performed, useful for customers, auditors and regulators.

Frequently asked questions

What clients usually ask before we start

What is the difference between a vulnerability scan and a penetration test?

A scan is automated and lists potential weaknesses. A penetration test validates them manually, exploits them in a controlled way and uncovers flaws no tool detects, such as business logic errors.

What are black, gray and white box tests?

It depends on how much information you give us: none (black box, like an external attacker), credentials or partial documentation (gray box) or full access to documentation and code (white box). Gray box usually offers the best balance between realism and coverage.

Can the test affect our production systems?

We use controlled techniques, exclude destructive actions and agree on testing windows. If you prefer, we can test a staging environment equivalent to production.

How often should we run a penetration test?

At least once a year and whenever there are significant changes to your applications or infrastructure. PCI DSS, for example, requires that frequency.

Does it help with SBS, PCI DSS or ISO 27001 compliance?

Yes. Our reports are structured to serve as evidence for auditors and regulators, and the attestation letter certifies that the test was performed.

Other services

A comprehensive view of your security

Source Code Review

We find vulnerabilities in your code before they reach production, in any language.

Social Engineering & Awareness

Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)