Offensive Security

Vulnerability assessment and penetration testing.

Focused, adversarial testing for teams that need to prove their security holds up. Every engagement is scoped by hand and tested by a senior operator, with a report written in plain language your board and your engineers can both act on.

How we test

  • PTES methodology
  • OWASP Top 10 + API + Mobile
  • OWASP Top 10 for LLMs
  • OSCP + CISSP led

One free retest within 120 days

Remediated Critical, High, and Medium findings retested at no extra charge after the final report.

Fig. A · Testing spec

Built for the audit and the customer review.

For teams preparing for SOC 2, ISO 27001, PCI DSS, or a customer security review, and for anyone shipping a new application, API, or AI feature who wants a regular testing cadence rather than a one-time scramble. If a prospect, auditor, or cyber-insurer has asked for a penetration test, start here.

Testing follows the Penetration Testing Execution Standard (PTES) and the relevant OWASP guides, run safely and non-destructively against the targets you approve. We don’t run load, stress, or denial-of-service tests, and we touch production only where you direct it. Critical findings are reported the moment they’re confirmed rather than held for the final report.

What we test.

Available individually or bundled into a program. Every service includes quality assurance, a full report, a live findings review, and one retest of remediated Critical, High, and Medium findings at no extra charge.

External network penetration test

A simulated attack from the internet against your public perimeter. We enumerate reachable hosts and services, safely validate which weaknesses are actually exploitable, and chain them to show whether initial access could lead to a broader compromise.

External vulnerability assessment

A broad, scan-led sweep of a larger IP range to surface known vulnerabilities and flag the hosts that warrant deeper testing. Lighter and faster than a full penetration test, it keeps a wide perimeter under regular watch between deeper engagements.

Web application penetration test

An authenticated, manual-led assessment against the OWASP Top 10 and beyond: broken access control, injection, session handling, business-logic abuse, and privilege escalation across user roles. Automated tooling maps the surface; the significant findings come from hands-on testing.

API penetration test

APIs carry the data and the logic, and they are attacked differently from the front end. We test REST, GraphQL, and similar interfaces against the OWASP API Security Top 10, with particular focus on object- and function-level authorization, where most real API breaches begin.

Mobile application penetration test

A full iOS and Android assessment against the OWASP Mobile Top 10: the client binary, data storage, transport and cryptography, session handling, and the APIs the app depends on. Manual testing surfaces the reverse-engineering and business-logic flaws scanners miss.

AI / LLM application penetration test

An adversarial assessment of an AI or LLM-enabled feature, aligned to the OWASP Top 10 for LLMs. We test model endpoints, retrieval and RAG pipelines, and tool integrations for prompt injection, insecure output handling, sensitive-data disclosure, and excessive agency.

Internal network penetration test

An assessment from the position of an attacker who already has a foothold inside, whether through a phished laptop, a rogue device, or a compromised vendor. We test segmentation, privilege escalation, credential exposure, and lateral movement to show how far an intruder could reach and what it would take to stop them.

Also available.

Scoped on request and often bundled into a program.

  • Secure code review
    Manual review of security-critical source paths, including authentication, cryptography, access control, and input handling, alongside or in place of black-box testing.
  • Wireless security assessment
    Corporate and guest Wi-Fi tested for rogue access, weak authentication, and segmentation failures.
  • Social engineering
    Controlled phishing and pretext campaigns to measure how people and process respond, with awareness debriefs afterward.
  • Cloud configuration review
    AWS, Azure, or GCP accounts assessed for identity, exposure, and misconfiguration against provider benchmarks.

What you get, every time.

Written for the board and the engineers in the same document.

  • A Report of Findings with a jargon-free executive summary and risk and remediation matrices ranked by business impact rather than raw severity.
  • Detailed findings with evidence, reproduction steps, and a specific, prioritized fix for each.
  • A short executive report for stakeholders, boards, and customers.
  • A live findings review to walk your team through the results and answer questions.
  • One free retest of remediated Critical, High, and Medium findings within 120 days of the final report.
  • On request, a signed security certificate confirming the testing performed and the findings remediated, to share with customers and auditors.

Buy a service, or run a program.

Single services suit a one-off need. Most teams get better coverage from a bundle sized to their stack, or an annual program that keeps testing on the cadence auditors and insurers expect.

Perimeter Baseline

The compliance and cyber-insurance starting point.

  • External network penetration test
  • External vulnerability assessment
  • Report, findings review, and one retest

Program A

Book a consult
Product Security Assurance

Full coverage for a multi-surface platform.

  • Web and API penetration tests
  • Mobile application test, iOS and Android
  • External network penetration test
  • Report, findings review, and one retest

Program C

Book a consult
Annual Assurance Program

Continuous coverage, planned for the year.

  • Scheduled testing across your stack
  • Quarterly external vulnerability sweeps
  • Priority scheduling and retests

Program D · annual, tested quarterly

Book a consult

Any of these services can be combined into a bespoke bundle. Every engagement is scoped in a conversation and priced in a fixed-fee Statement of Work, so there are no surprise change orders. Book a consult and we’ll recommend the right fit.

How an engagement runs.

From signed scope to retest, a typical single-service engagement runs two to four weeks. Larger programs are staged so your team is never blocked waiting on a report.

  1. 01
    Scope
    You tell us what you’re shipping; we confirm targets, roles, environment, and rules of engagement, then issue a fixed-fee Statement of Work.
  2. 02
    Kick-off
    A 30-minute call to confirm access, credentials, test windows, and the emergency contact. A start date is set.
  3. 03
    Testing
    Safe, controlled testing against the approved scope, with weekly status updates and any Critical finding reported immediately on discovery.
  4. 04
    Reporting
    You receive the draft Report of Findings and the executive report, with risk-rated findings and a prioritized remediation plan.
  5. 05
    Findings review
    A live session to walk through results, answer questions, and agree priorities. The final report issues after your review.
  6. 06
    Retest and certificate
    Once you’ve remediated, we retest the fixes at no charge within 120 days and, on request, issue a signed security certificate.

Simple contracts, independent results.

Three documents stand behind every engagement, and none of them is a surprise.

Every engagement runs under a mutual NDA before anything sensitive is shared, a short Master Services Agreement, and a per-engagement Statement of Work that defines scope, deliverables, and rules of engagement. Where a test must serve as independent assurance for a PCI DSS assessment, SOC 2 audit, or customer security review, SECURIQUE keeps the vCISO and testing roles separate for that scope, or brings in an independent tester.

Book a consult.

Tell us what you’re shipping or what an auditor or customer has asked for, and we’ll turn it into a scoped, fixed-fee engagement. The person who scopes it is the person who tests it.