Services

Penetration testing services.

Nine engagement types across applications, APIs, AI systems, cloud, infrastructure and compliance. Every engagement is scoped in writing before it starts, run by a certified operator, and closed with a retest. Based in Dhaka, we are a penetration testing company in Bangladesh providing VAPT services across Bangladesh and worldwide.

Scope an engagement →
Application security

Web Application Pentest

Grey-box testing with credentials for every role you want covered. Business logic and access control get the same attention as the injection classes a scanner finds.

Scope
Authenticated and unauthenticated paths, each user role and tenant boundary, session handling, password reset and MFA flows, file upload and export, and any admin surface you include.
Method
OWASP WSTG, with manual exploitation and chaining. Scanner output is used for coverage, never reported without validation.
Deliverable
Findings rated with CVSS v3.1, each with reproduction steps, request and response evidence, and remediation notes written for engineers. One retest after fixes.
Application security

Mobile Application Pentest

Android and iOS builds tested as a whole system: the compiled app, what it writes to the device, and the backend it talks to.

Scope
Static and dynamic analysis of the build, local storage and keychain use, certificate pinning and traffic interception, IPC, deep links and exported components. Backend APIs included by agreement.
Method
OWASP MASVS on rooted and jailbroken devices, plus a stock device where a control only holds on unmodified platforms.
Deliverable
One report per platform, with the device and OS version each finding was reproduced on. Retest after fixes.
Application security

API Pentest

REST, GraphQL and service-to-service interfaces tested against their real behaviour, including endpoints the specification does not mention.

Scope
Object and function level authorisation per role, authentication and token handling, mass assignment, injection, rate limiting and resource consumption. GraphQL introspection, depth and batching where applicable.
Method
OWASP API Security Top 10. The provided OpenAPI or GraphQL schema is reviewed first, then compared against what the API actually accepts.
Deliverable
Findings with the exact requests that reproduce them, ready to replay. Retest after fixes.
AI security

AI & LLM Pentest

Model-backed features tested as attack surface: the prompts, the tools the model can call, the data it retrieves, and the agents that chain them.

Scope
Direct and indirect prompt injection, system prompt extraction, tool invocation and excessive agency, retrieval and embedding poisoning, output handling in downstream systems, and cost or quota abuse.
Method
OWASP Top 10 for LLM Applications and MITRE ATLAS, tested against the running application rather than the model in isolation.
Deliverable
Findings with the prompts and payloads that trigger them, and the downstream impact each one produced. Retest after fixes.
Infrastructure

Network & Infra Pentest

External or internal, or both. The goal is the path from one exposed service to the access that actually matters.

Scope
Host and service discovery, patch and configuration weaknesses, default and reused credentials, network segmentation, and privilege escalation and lateral movement from an assumed foothold.
Method
NIST SP 800-115 and PTES. Exploitation is agreed in the rules of engagement before testing starts.
Deliverable
Findings with affected hosts, the path taken, and remediation ordered by what closes the most exposure. Retest after fixes.
Adversary simulation

Red Teaming Exercises

An objective-led exercise against your live environment. It measures detection and response as much as exploitability, so it suits teams that already run a SOC.

Scope
Agreed objectives such as reaching a system, a dataset or a level of access. Initial access, persistence, privilege escalation and exfiltration paths, within the constraints set in the rules of engagement.
Method
Techniques mapped to MITRE ATT&CK. Every action is timestamped and logged so your team can reconstruct the timeline afterwards.
Deliverable
Attack narrative with the ATT&CK mapping, a detection gap analysis against what your tooling recorded, and a purple team debrief.
Continuous assurance

Vulnerability Assessment

Breadth over depth. Useful when you need regular coverage of a large estate rather than deep exploitation of one application.

Scope
Authenticated and unauthenticated scanning across the hosts and applications in the agreed inventory, on a one-off or recurring schedule.
Method
Automated scanning with manual triage. Every finding is verified by an operator before it reaches you, so false positives do not become tickets.
Deliverable
Prioritised findings with CVSS scores, plus a comparison against the previous cycle showing what was fixed, what regressed and what is still open.
Cloud

Cloud Security Audit

Six engagement types across your cloud provider, deployment pipeline and container platform, run by the same certified operators as every other engagement.

Cloud Penetration Testing

Manual testing of your AWS, Azure or GCP environment for exploitable misconfiguration and privilege-escalation paths.

Cloud Security Assessment

A configuration review against your provider's security benchmark, covering IAM, storage, networking and logging.

CI/CD Pipeline Security Assessment

Testing of the build and deployment pipeline itself — secrets handling, runner permissions and supply-chain exposure.

Container Security Assessment

Image and runtime review covering base-image vulnerabilities, privilege escalation and container escape paths.

Kubernetes Security Assessment

Cluster configuration review — RBAC, network policy, secrets and the control plane's exposed surface.

Microservices Penetration Testing

Service-to-service testing across your microservices architecture, including inter-service authentication and trust boundaries.

Compliance

Compliance Readiness Assessment

Five engagement types built around the evidence your auditor or assessor actually asks for, run by the same certified operators as every other engagement.

PCI DSS Penetration Testing

Testing scoped to Requirement 11.3, covering the cardholder data environment and any system connected to it.

ISO 27001 Security Assessment

A technical readiness check against Annex A controls ahead of certification or a surveillance audit.

SOC 2 Security Testing

Evidence-generating testing mapped to the Security and Availability trust service criteria your auditor will ask for.

HIPAA Security Testing

Testing focused on systems that store, process or transmit ePHI, aligned to the HIPAA Security Rule.

Compliance Gap Assessment

A framework-agnostic review that flags the gaps between your current controls and the standard you are working towards.

Define the scope of your security assessment.

Scope an engagement →