Skip to content

Guide

Brief and to the point about what we do and why. So you understand what you are paying for before the first call.

Articles

Pentest and audit

What a pentest is and how it differs from a vulnerability scanner

A scanner finds known holes from a list. A pentester thinks like an attacker and chains small things into a real breach.

4 min read
Pentest and audit

Types of pentest: web, API, mobile apps, infrastructure, cloud, people

Each type checks its own layer. Together they give the picture, separately only a fragment.

5 min read
Pentest and audit

How to prepare for a pentest so you do not overpay

Five things done before the start that save days of work.

3 min read
Pentest and audit

What a pentest report must contain

If only the pentester understands the report, it does not work. A checklist for judging any report.

3 min read
Bug sweeps

How a bug sweep works

What we do in an office, a car or a flat, which instruments we use and why it takes hours.

5 min read
Bug sweeps

Signs that you may be listened to

None of them is proof, but two or three together are a reason to check.

3 min read
Devices and communications

GrapheneOS: what it is and who really needs it

An operating system for Pixel without Google services by default. Not for everyone, but for some the only option.

4 min read
Devices and communications

Secure communications: messengers, email, hardware keys

Three things that close most real risks for a person, not for a server.

4 min read
Compliance

ISO 27001 or SOC 2: which to choose

Both are about managing security systematically. The difference is who you prove it to.

4 min read
Compliance

NIS2 and DORA: who is affected and what to do

Two European frameworks that turn cybersecurity from a recommendation into an obligation with management liability.

4 min read

Terms

Words you will hear from us and from auditors. Reports are hard to read without them.

Pentest
Penetration test: a controlled attack on a system with the owner's permission, to find ways in before others do.
Vulnerability
A weak spot in a system through which the confidentiality, integrity or availability of data can be violated.
Exploit
A method or code that uses a vulnerability to get a result: access, data, command execution.
CVSS
A 0 to 10 scale for rating the severity of a vulnerability. Above 9 means critical.
OWASP
A community that publishes methodologies and lists of the most common vulnerabilities in web and mobile apps (Top 10, WSTG, MASVS).
Red team
A simulation of a real targeted attack on a company without warning most employees, to test detection and response.
Social engineering
An attack on people rather than technology: phishing, calls from "support", a request to hold the door.
Phishing
A forged email, website or message that makes you enter a password or open a file.
ISMS
Information security management system: the policies, roles, risks and controls required by ISO 27001.
Gap analysis
A comparison of the current state with the requirements of a standard or regulator. The result: a list of gaps and a plan.
vCISO
Virtual chief information security officer: an external expert who performs the CISO role part-time, without a staff position.
TSCM
Technical surveillance countermeasures: the search for hidden microphones, cameras, trackers and transmitters.
Planted device
A hidden microphone, camera, GPS tracker or transmitter installed without the knowledge of the owner of the premises or car.
Non-linear junction detector
An instrument that finds semiconductor electronics even when switched off: bugs in walls, furniture, gifts.
Spectrum analyser
An instrument that shows all radio transmissions in a range and lets you tell legitimate ones (Wi-Fi, mobile) from foreign ones.
GrapheneOS
A hardened operating system for Google Pixel without built-in Google services, with strengthened app isolation.
Hardware key
A physical device (FIDO2, for example YubiKey) for logging into an account. Cannot be intercepted like an SMS code.
End-to-end encryption
Only the recipient decrypts the message; the intermediary server sees only encrypted data.
Threat model
The answer to the question: from whom, what and at what cost are you protecting. It defines which measures are needed and which are excessive.
NDA
Non-disclosure agreement. Signed before any work begins.

Common questions

How much does a pentest cost?

It depends on the scope: the number of applications, the size of the network, the access mode. A small web app and a large infrastructure differ many times over. After a short conversation we give a fixed price and timeline; we do not publish prices on the site because without scope they mislead.

Will you break something during the pentest?

We work within agreed boundaries and rules: no DoS, no data destruction, destructive actions only in a test environment and after separate permission. We warn about risky steps in advance.

How long does the work take?

A pentest of one application: one to two weeks including the report. Infrastructure: two to four weeks. A bug sweep: from a few hours to a day. ISO 27001 preparation: three to nine months depending on the starting point.

Do you sign an NDA?

Yes, before any work begins. We can sign your template or provide ours.

Can I contact you anonymously?

Yes. The form has a confidential mode: no name or phone, only a Signal or Session handle. For a bug sweep we arrange a meeting without witnesses.

Do you work outside Ukraine?

Yes, with EU customers remotely for pentesting and compliance, and on site for sweeps by arrangement.

Do you issue a certificate after a pentest?

We issue a report and a letter confirming that the testing and the retest were performed. An ISO 27001 certificate is issued only by an accredited body; we prepare you for it.

What happens if you find a bug?

We do not touch the device until you decide: we record it, photograph it and write a protocol. Then either removal or, on lawyers' advice, involving law enforcement while preserving evidence.

Write to us

The message goes straight to our Telegram. Nothing stays on the server.

Telegram

What you need

By sending the form you agree that we contact you through the channel you provided.