Find the holes before someone else does.
Manual penetration testing of web apps, APIs, mobile, cloud and networks for Australian organisations. Onshore testers, a fixed quote in AUD, and a free retest.
Web, API, mobile, cloud and network
Scope, test, report, retest
You will know what we are testing, when we are testing it, and what we found. Full methodology.
Scope
A short call to lock targets, roles and rules of engagement. Fixed quote in AUD before anyone touches a system.
Test
Manual testing mapped to OWASP and PTES. Daily check-ins. A phone call the same day if we confirm anything critical.
Report
CVSS 3.1, reproduction steps, evidence and a concrete fix, plus an executive summary a board can read.
Retest
You fix. We verify at no extra cost and issue an updated report with an attestation letter.
The things Australian buyers actually check
Onshore
Testers and evidence stay in Australia. We work AEST and AWST, not a follow-the-sun queue in another timezone.
Manual-first
Scanners for breadth. A human for access control, business logic and the chain that turns a medium into an incident.
Senior delivery
The person who scopes the work is the person who tests it. No bait-and-switch from the sales call to Monday morning.
Evidence, not theatre
Reports structured for ISO 27001, SOC 2, PCI DSS, APRA CPS 234 and the ACSC Essential Eight. We do not invent CREST or IRAP we do not hold.
Government, finance, healthcare and SaaS
Government
Essential Eight and ISM-aware reporting for department questionnaires.
Essential Eight >Financial services
APRA CPS 234 control testing a risk committee can actually use.
CPS 234 >Healthcare
Patient portals and clinical systems under the Privacy Act.
Healthcare >SaaS
Multi-tenant apps, SOC 2 and ISO 27001 for the first enterprise deal.
SaaS >Guides for people who buy tests
How much does a penetration test cost in Australia?
Indicative AUD bands and how to compare quotes without getting played.
Read post >ISO 27001 penetration testing in Australia
Where independent testing sits in Annex A, and what an auditor looks for.
Read post >What is penetration testing?
What happens during a real test, and how to spot a rebadged scan.
Read post >Request a quote
Tell us the application, the cloud tenancy or the network. A fixed quote in AUD, usually within two Australian business days.