// About

A testing practice, not a scan franchise

VAPT.COM.AU exists because too many 'penetration tests' sold in Australia are a scanner run, a logo swap and an invoice. We think the work should be done by hand, explained in plain English, and priced before it starts.

A contemporary office corridor

Who we are

We are an Australian offensive-security practice. We break into applications, APIs, cloud tenancies and networks with permission, then we write it down so someone can fix it. We work with startups shipping their first enterprise deal, with mid-market teams facing ISO 27001 or SOC 2, and with organisations whose customers have started asking adult questions about security.

We stay deliberately small. The person who scopes the work is the person who tests it. There is no bait-and-switch from a senior on the sales call to whoever was free on Monday.

Working through a test scope at a desk
// evidence an auditor will accept, first time

What we believe

  • A finding you cannot reproduce is a rumour. Every issue we report has steps and evidence.
  • The report is the product. If engineers cannot act and leadership cannot understand, the test was wasted.
  • Scope should fit the question you are trying to answer, not the largest number we could quote.
  • Retesting is part of the job. Charging extra to confirm you fixed it is a racket.
  • Claims should be true. We do not invent CREST, IRAP or ISO certificates on this site. The work is the credential.

How we handle data

Findings and evidence are stored encrypted, shared only with named contacts, and deleted on an agreed schedule after the engagement closes. Testers are onshore. Read the privacy notice.

Sister sites

VAPT.COM.AU is the Australian practice. We are not a reskin of an overseas brand. If you need testing in another jurisdiction, ask. Do not assume the same legal overlay applies.

Work with us

Tell us what you are building and what you need to prove, to a customer, an auditor, or yourselves.

Get a fixed quote