Accepting new projects

Find the gap before attackers do.

We test your systems with real attacker techniques. Every finding is reported with proof, impact and remediation.

27+Attack categories
OWASPWSTG methodology
72 hrCritical finding notice
Two-layer reportExecutive summary + technical detail
Proven findingsNot "might be" — "reached via these steps"
Free retestVerification after remediation
Services

What we test

Eight areas, one output: a report showing what can break and how to close it.

Web Application Testing

Login, session, authorization and data layer. Manual testing to OWASP WSTG.

SQLiXSSAccess controlSSRF

API & Mobile

REST, GraphQL and gRPC endpoints plus Android/iOS client analysis.

JWTOAuthIDORAPK/IPA

Cloud & Infrastructure

Misconfigurations in your cloud account and services left exposed.

S3/GCSIAMKubernetesCI/CD

Phishing Simulation

How would your staff react to a real attack? We measure it.

ScenariosClick rateTraining

Active Directory

We map the full path an attacker would take through your internal network.

KerberoastingNTLM relayLateral movement

Continuous Monitoring

Monthly scanning and rapid checks for newly disclosed vulnerabilities.

Monthly reportCVE watchAlerts

Data Protection Compliance

We prepare the evidence for technical measures required in audits.

Gap analysisLog reviewAudit report

Incident Response

Rapid technical review when something looks wrong. Understand without destroying evidence.

EmergencyWebshellRoot cause

Same deliverable on every engagement: executive summary, technical report (evidence + reproduction steps), remediation plan and a free verification round.

Industries

We know your sector

Every sector has its own risk profile and regulatory load. We build the test scenarios around it.

Finance & Fintech

Payment flows, card data, open banking APIs. Authorization and transaction integrity testing with a regulatory lens.

Healthcare

Patient data privacy, hospital and appointment systems, medical device networks. Special-category data requirements.

E-commerce & Retail

Cart and payment logic, coupon and discount abuse, stock manipulation, customer account takeover scenarios.

Hotel & Tourism

Booking systems, guest network segmentation (WiFi isolation), PMS integrations, kiosk security.

Government & Municipal

Public service integrations, internal network segmentation, privileged account management, document sharing systems.

Technology & SaaS

Multi-tenant architecture, tenant isolation, CI/CD pipelines, embedded API key leakage.

Case Notes

What we find, how it closes

These scenarios illustrate common finding types in the field. Client names and system details are not shared, for confidentiality.

E-commerce Critical

Unauthorized order disclosure

Issue

The order detail page opened by order number; changing the number exposed another customer's order, address and invoice data.

Impact

Customer data disclosure and data protection breach risk. Automated number enumeration could pull the entire order history.

Fix

Server-side ownership check added; order number replaced with a session-bound key. Proven closed in the verification round.

Fintech Critical

Privilege escalation chain in the API

Issue

User role was held client-side. Changing the role field in the request body granted access to admin endpoints from a standard account.

Impact

Account takeover and bulk data access were possible. Money-moving endpoints were reachable the same way.

Fix

Role moved server-side; authorization verified on every request. Second-factor confirmation added for sensitive operations.

Hospitality High

Broken isolation on the guest network

Issue

The guest WiFi network shared a segment with reception and accounts machines. Any user on the network could see internal systems.

Impact

A guest could attempt access to internal devices during their stay, targeting door-card and reservation systems.

Fix

Guest network moved to a separate VLAN, client-to-client traffic disabled. Management interfaces restricted to an authorized segment.

Packages

Transparent pricing

Starting prices. A firm written quote follows the free initial assessment.

Starter

Single application
19,900 ₺ + VAT
  • Web application testing
  • Automated + manual verification
  • Findings and remediation advice
  • 1 retest round
  • Delivery: 5 business days
Get a Quote

Enterprise

Multiple systems
On request
  • Multiple applications and internal network
  • Active Directory scenarios
  • Phishing simulation included
  • Container & CI/CD security
  • Priority contact channel
Get a Quote

Monthly Monitoring

Subscription
7,900 ₺ / month + VAT
  • Monthly surface scan
  • Rapid CVE checks
  • Remediation tracking report
  • Instant alert on critical findings
  • 3-month term, then cancel anytime
Get a Quote
Difference

How we differ from scan-only vendors

Manual testing, tool-assisted

Scanners catch known patterns. Chained scenarios need a human. We use both — neither replaces the other.

No false alarms

Every finding is reported only after its exploitability is confirmed. Not a version list — a real scenario.

A report you can read

The executive summary is plain; the technical section is full of copyable commands. Hand it to your developer.

With you until it's fixed

We don't drop the report and leave. The verification round proves the gaps actually closed.

FAQ

Common questions

Will testing take our systems down?

No. Tests run in a maintenance window with pre-agreed load limits. Tests that could affect production are never run without your written approval.

Is our data safe?

A confidentiality agreement is signed before testing. Personal data accessed is never included in the report — only masked samples. All access is removed at project end.

How long does it take?

A single application takes about 5 business days, web + API 10 business days, enterprise scope 3-4 weeks. The schedule is confirmed in the initial assessment.

Do you verify the fixes?

Yes. Depending on the package, 1-2 free verification rounds are included. Findings are retested and the result is reported in writing.

Which systems will you not test?

Only systems you have written authority over. Targets outside the scope agreement, and assets whose ownership cannot be proven, are excluded — that protects both of us.

Does finding a vulnerability create legal risk for us?

No. Because testing is performed under contract, you are protected. Findings are reported only to you and never shared with third parties.

Contact

Free initial assessment

Send us your system address and a short scope. Within 24 hours you get a written reply with the tests required, the timeline and a price range. No obligation.

RequestFill in the form below
Response timeWithin 24 hours
ContractScope (RoE) + confidentiality (NDA)

Send your request and we will respond within 24 hours. Mention any urgency in the form.