Offensive Security
Vulnerability assessment and penetration testing.
Focused, adversarial testing for teams that need to prove their security holds up. Every engagement is scoped by hand and tested by a senior operator, with a report written in plain language your board and your engineers can both act on.
How we test
- PTES methodology
- OWASP Top 10 + API + Mobile
- OWASP Top 10 for LLMs
- OSCP + CISSP led
One free retest within 120 days
Remediated Critical, High, and Medium findings retested at no extra charge after the final report.
Fig. A · Testing spec
Built for the audit and the customer review.
For teams preparing for SOC 2, ISO 27001, PCI DSS, or a customer security review, and for anyone shipping a new application, API, or AI feature who wants a regular testing cadence rather than a one-time scramble. If a prospect, auditor, or cyber-insurer has asked for a penetration test, start here.
Testing follows the Penetration Testing Execution Standard (PTES) and the relevant OWASP guides, run safely and non-destructively against the targets you approve. We don’t run load, stress, or denial-of-service tests, and we touch production only where you direct it. Critical findings are reported the moment they’re confirmed rather than held for the final report.
What we test.
Available individually or bundled into a program. Every service includes quality assurance, a full report, a live findings review, and one retest of remediated Critical, High, and Medium findings at no extra charge.
External network penetration test
A simulated attack from the internet against your public perimeter. We enumerate reachable hosts and services, safely validate which weaknesses are actually exploitable, and chain them to show whether initial access could lead to a broader compromise.
External vulnerability assessment
A broad, scan-led sweep of a larger IP range to surface known vulnerabilities and flag the hosts that warrant deeper testing. Lighter and faster than a full penetration test, it keeps a wide perimeter under regular watch between deeper engagements.
Web application penetration test
An authenticated, manual-led assessment against the OWASP Top 10 and beyond: broken access control, injection, session handling, business-logic abuse, and privilege escalation across user roles. Automated tooling maps the surface; the significant findings come from hands-on testing.
API penetration test
APIs carry the data and the logic, and they are attacked differently from the front end. We test REST, GraphQL, and similar interfaces against the OWASP API Security Top 10, with particular focus on object- and function-level authorization, where most real API breaches begin.
Mobile application penetration test
A full iOS and Android assessment against the OWASP Mobile Top 10: the client binary, data storage, transport and cryptography, session handling, and the APIs the app depends on. Manual testing surfaces the reverse-engineering and business-logic flaws scanners miss.
AI / LLM application penetration test
An adversarial assessment of an AI or LLM-enabled feature, aligned to the OWASP Top 10 for LLMs. We test model endpoints, retrieval and RAG pipelines, and tool integrations for prompt injection, insecure output handling, sensitive-data disclosure, and excessive agency.
Internal network penetration test
An assessment from the position of an attacker who already has a foothold inside, whether through a phished laptop, a rogue device, or a compromised vendor. We test segmentation, privilege escalation, credential exposure, and lateral movement to show how far an intruder could reach and what it would take to stop them.
Also available.
Scoped on request and often bundled into a program.
-
Secure code reviewManual review of security-critical source paths, including authentication, cryptography, access control, and input handling, alongside or in place of black-box testing.
-
Wireless security assessmentCorporate and guest Wi-Fi tested for rogue access, weak authentication, and segmentation failures.
-
Social engineeringControlled phishing and pretext campaigns to measure how people and process respond, with awareness debriefs afterward.
-
Cloud configuration reviewAWS, Azure, or GCP accounts assessed for identity, exposure, and misconfiguration against provider benchmarks.
What you get, every time.
Written for the board and the engineers in the same document.
- A Report of Findings with a jargon-free executive summary and risk and remediation matrices ranked by business impact rather than raw severity.
- Detailed findings with evidence, reproduction steps, and a specific, prioritized fix for each.
- A short executive report for stakeholders, boards, and customers.
- A live findings review to walk your team through the results and answer questions.
- One free retest of remediated Critical, High, and Medium findings within 120 days of the final report.
- On request, a signed security certificate confirming the testing performed and the findings remediated, to share with customers and auditors.
Buy a service, or run a program.
Single services suit a one-off need. Most teams get better coverage from a bundle sized to their stack, or an annual program that keeps testing on the cadence auditors and insurers expect.
The compliance and cyber-insurance starting point.
- External network penetration test
- External vulnerability assessment
- Report, findings review, and one retest
For a SaaS product and the API behind it.
- Web application penetration test
- API penetration test, same product
- Report, findings review, and one retest
Full coverage for a multi-surface platform.
- Web and API penetration tests
- Mobile application test, iOS and Android
- External network penetration test
- Report, findings review, and one retest
Continuous coverage, planned for the year.
- Scheduled testing across your stack
- Quarterly external vulnerability sweeps
- Priority scheduling and retests
Any of these services can be combined into a bespoke bundle. Every engagement is scoped in a conversation and priced in a fixed-fee Statement of Work, so there are no surprise change orders. Book a consult and we’ll recommend the right fit.
How an engagement runs.
From signed scope to retest, a typical single-service engagement runs two to four weeks. Larger programs are staged so your team is never blocked waiting on a report.
-
01ScopeYou tell us what you’re shipping; we confirm targets, roles, environment, and rules of engagement, then issue a fixed-fee Statement of Work.
-
02Kick-offA 30-minute call to confirm access, credentials, test windows, and the emergency contact. A start date is set.
-
03TestingSafe, controlled testing against the approved scope, with weekly status updates and any Critical finding reported immediately on discovery.
-
04ReportingYou receive the draft Report of Findings and the executive report, with risk-rated findings and a prioritized remediation plan.
-
05Findings reviewA live session to walk through results, answer questions, and agree priorities. The final report issues after your review.
-
06Retest and certificateOnce you’ve remediated, we retest the fixes at no charge within 120 days and, on request, issue a signed security certificate.
Simple contracts, independent results.
Three documents stand behind every engagement, and none of them is a surprise.
Every engagement runs under a mutual NDA before anything sensitive is shared, a short Master Services Agreement, and a per-engagement Statement of Work that defines scope, deliverables, and rules of engagement. Where a test must serve as independent assurance for a PCI DSS assessment, SOC 2 audit, or customer security review, SECURIQUE keeps the vCISO and testing roles separate for that scope, or brings in an independent tester.
Book a consult.
Tell us what you’re shipping or what an auditor or customer has asked for, and we’ll turn it into a scoped, fixed-fee engagement. The person who scopes it is the person who tests it.