Services
Each service below is offered independently. Nothing is bundled, and nothing is quoted before we understand what we are testing.
01 · Assessment
Authenticated and unauthenticated assessment across the OWASP Top 10, weighted toward the classes automated scanners consistently miss. Testing is manual first; tooling is used to widen coverage, never to produce the report.
02 · Pre-production
For an application approaching production. The objective is not a long finding list — it is that you launch without a class of problem you could have caught cheaply.
03 · Continuous
Most organisations cannot list what they expose. This service maintains that list for you and tells you when it changes — because the host nobody remembered is the one that gets breached.
04 · Assessment
Android assessment combining static review of the shipped package with runtime instrumentation on a live device — because what the code says and what the app does at runtime are frequently different.
05 · Closure
Finding a vulnerability is the cheap half. This service covers the expensive half — getting it actually fixed, and proving it.
How findings are rated
We use the five-tier scale common to coordinated disclosure programmes, so a HEBTECH report slots straight into the triage process your team already runs.
Full account or infrastructure compromise; unrestricted access to other customers’ data. Reported within 24 hours, ahead of the report.
Authentication or access-control bypass, stored XSS in an authenticated context, SSRF reaching internal services. Reported within 48 hours.
Reflected XSS and CSRF through to hardening gaps and informational items. Delivered with the report, each with a specific fix.
Send the scope and objective. You receive a written response with an approach, a timeline and a fixed quotation — no obligation, no automated sales sequence.