All services
01
Black Box Penetration Test
External, zero-knowledge testing that mirrors how a determined attacker probes your perimeter without inside help. We work from nothing but your organisation name and agreed targets, mapping what is publicly reachable and attempting safe, controlled exploitation.

Scope
- External recon and OSINT against agreed domains and IP ranges
- Web application, API, and network perimeter testing
- Unauthenticated exploitation of public-facing assets
- Credential exposure and leaked data checks
- Safe, non-destructive proof-of-exploit for every confirmed finding
Deliverables
- Executive summary written for non-technical stakeholders
- Technical findings with CVSS ratings and reproduction steps
- Prioritised remediation roadmap with effort estimates
- Live debrief walkthrough with your engineering team
- Free retest of critical and high findings
Typical timeline
1–3 days
Scope call & NDA
Free 30-minute call, mutual NDA, fixed-fee proposal.
5–10 business days
Testing window
Active testing with daily progress updates.
3–5 business days
Reporting
Draft report, QA review, and final delivery.
Within 30 days
Debrief & retest
Walkthrough session plus retest of critical findings.