services

Security done right

From a one-off check to ongoing support. Pricing depends on the scope of work, number of devices and the state of your infrastructure — a precise quote is prepared after a consultation.

🛡️

Penetration Testing

External and internal pentest of infrastructure, web apps, APIs and mobile apps.

  • External perimeter and internal network
  • Web, API, mobile applications
  • Report with reproduction steps and recommendations
🎯

Bug Bounty & Program Management

Launch and run a rewards program, triage findings with a community of researchers.

  • Scope and program rules setup
  • Triage and validation of reports
  • Community of vetted researchers
🧩

Infrastructure Audit

Comprehensive assessment of servers, networks and configurations against security standards.

  • Inventory and attack-surface analysis
  • Configuration review and hardening
  • Vulnerability prioritization by risk
☁️

Cloud Security

Audit of AWS / GCP / Azure configurations, IAM, secrets and network policies.

  • CSPM and access (IAM) review
  • Secrets and key management
  • Network isolation and least privilege
⚔️

Red Team

Simulation of a targeted attack to test detection and response readiness.

  • Real-adversary scenarios (TTPs)
  • Blue Team and monitoring validation
  • Escalation and lateral-movement paths
🎭

Social Engineering

Phishing campaigns and human-factor testing with staff training.

  • Targeted phishing simulations
  • Staff awareness assessment
  • Report and training materials
🌐

Web Application Audit

Deep OWASP analysis: injections, authentication, business-logic flaws, access control.

  • OWASP Top 10 and business logic
  • Authorization and session checks
  • Manual and automated analysis
🚨

Incident Response

Help during a breach: containment, investigation, recovery and recommendations.

  • Forensics and trace analysis
  • Containment and threat removal
  • Recovery and prevention plan
🔧

Security & IT Outsourcing

Ongoing security and IT support: vCISO, monitoring, perimeter maintenance.

  • vCISO and security strategy
  • Continuous monitoring and hardening
  • Cost depends on infrastructure size
📋

Compliance & Standards

Preparation for standards and requirements: ISO 27001, PCI DSS, GDPR, SOC 2.

  • Gap analysis and roadmap
  • Policies and processes
  • Audit support
🎓

Training & Security Awareness

Staff awareness programs and hands-on cyber exercises.

  • Courses and practical training
  • Personal security checklists
  • Team progress metrics
🧬

Source Code Review

Manual and static code analysis to find vulnerabilities at the application level.

  • SAST and manual code review
  • Dependency check (SCA)
  • Secure development recommendations

Didn't find the service you need?

Describe your task — we'll tailor the format to your infrastructure.

Services — Palanit