@shv_founder ↗
Services / Penetration Testing Moscow · Worldwide

Pentest: find the path to data before they do

Black/grey-box attack on product and perimeter. Real chains to money and accounts — not green scanner checkmarks.

Why it matters

Without a pentest you pay either for a scanner’s false calm or for an incident. A leak, a locked-out admin panel, someone inside your CRM or Mini App — that’s money and reputation. A pentest shows whether you can be reached and what to fix first.

What we do

In this engagement:

  • Rules of engagement (RoE) — scope, no-go zones, attack windows, escalation channels before kickoff
  • Recon and exploitation — OSINT, attack surface, hands-on validation — not just scanner CVEs
  • Escalation and attack chains — from a weak link to data, admin, or adjacent services
  • Report for business and engineers — risk in money/scenarios plus repro steps and fixes for the team
  • Retest of critical findings — we verify the holes are closed, not just “accepted into backlog”

How we work

We lock RoE and scope first: what’s in play, what’s off-limits, who is on call during the test window. Critical findings go to chat immediately — we don’t wait for the final PDF. You get a prioritized report and a retest as agreed. Timeline depends on perimeter; scope and price are fixed after a short intake.

FAQ

How long does a pentest take and what do you need from us?

Typically from a few days to a few weeks — depends on scope: one product, admin panel, perimeter, integrations. From you: access per RoE, contacts for critical alerts, a no-go list. Exact timing is set after we review the perimeter, not a vague ballpark.

How is this different from a vulnerability scanner?

A scanner gives a list of possible issues and a lot of noise. A pentest checks whether that turns into a path to data, money, or system control — hands-on, with escalation and business context. You get what to fix first, not “a thousand mediums.”

Next / Your project

Describe the contour — we’ll lock window and RoE.