Services

Scoped, quoted and delivered one engagement at a time.

Each service below is offered independently. Nothing is bundled, and nothing is quoted before we understand what we are testing.

01 · Assessment

Web application penetration testing

Access controlBusiness logicSSRFInjectionAuth & session

Authenticated and unauthenticated assessment across the OWASP Top 10, weighted toward the classes automated scanners consistently miss. Testing is manual first; tooling is used to widen coverage, never to produce the report.

  • Broken access control and IDOR across every user role you supply
  • Business-logic abuse — the multi-step flows that only fail when chained
  • Server-side request forgery, injection, deserialisation and file-handling flaws
  • Authentication, session management, password reset and multi-factor bypasses
  • Every candidate finding reproduced end to end before it is written up

02 · Pre-production

Pre-launch security review

Threat modellingConfigurationSecrets & CI/CDFix verification

For an application approaching production. The objective is not a long finding list — it is that you launch without a class of problem you could have caught cheaply.

  • Threat model of the intended deployment, including third-party dependencies
  • Server, TLS and cloud configuration review against the deployment you will actually run
  • Secrets handling and CI/CD pipeline hygiene
  • Verification that remediation holds, before go-live rather than after

03 · Continuous

Attack-surface monitoring

SubdomainsJS analysisExposed keysChange alerts

Most organisations cannot list what they expose. This service maintains that list for you and tells you when it changes — because the host nobody remembered is the one that gets breached.

  • Subdomain and host discovery across your registered domains
  • JavaScript bundle analysis for undocumented endpoints and leaked keys
  • Forgotten staging, demo and legacy hosts absent from every inventory
  • A maintained live register with alerting when the surface changes

04 · Assessment

Mobile application assessment

Static reviewInstrumentationTransport securityIPC surfaces

Android assessment combining static review of the shipped package with runtime instrumentation on a live device — because what the code says and what the app does at runtime are frequently different.

  • Static review of the package: permissions, configuration, embedded material
  • Runtime instrumentation, traffic interception and certificate pinning assessment
  • Local and shared storage handling, including what survives uninstall
  • Exported components, deep links and IPC surfaces
  • The backing APIs the application consumes — often the softer target

05 · Closure

Remediation support & retest

Developer supportFormal retestClosure summary

Finding a vulnerability is the cheap half. This service covers the expensive half — getting it actually fixed, and proving it.

  • Direct support to your developers while fixes are implemented
  • Formal retest of every finding, included within 30 days of report delivery
  • A closure summary suitable for internal governance, audit, or enterprise customer security reviews

How findings are rated

A severity scale that reads the same as everyone else’s.

We use the five-tier scale common to coordinated disclosure programmes, so a HEBTECH report slots straight into the triage process your team already runs.

P1 Critical

Full account or infrastructure compromise; unrestricted access to other customers’ data. Reported within 24 hours, ahead of the report.

P2 High

Authentication or access-control bypass, stored XSS in an authenticated context, SSRF reaching internal services. Reported within 48 hours.

P3 – P5

Reflected XSS and CSRF through to hardening gaps and informational items. Delivered with the report, each with a specific fix.

Tell us what needs testing.

Send the scope and objective. You receive a written response with an approach, a timeline and a fixed quotation — no obligation, no automated sales sequence.

Request an engagement →