Security Testing That Finds
What Scanners Miss
Manual penetration testing and maturity assessments from people who read the code, not just the CVE feed. One team covers pentest, OpenSAMM, threat modeling, Vulnix0-powered offensive testing, AquilaX code & infrastructure review, and phishing simulation — so you're not stitching reports together from five vendors.
Where We Start
Most clients come to us with one problem, not six. Pick the one that matches yours — we'll tell you honestly if you need more.
Penetration Testing
Hands-on, adversary-style testing of web, API, network, cloud, and wireless environments — validating what an attacker could actually reach and exploit.
OpenSAMM Assessment
OWASP SAMM-based maturity review of your software security practices, scored across governance, design, implementation, verification and operations.
Threat Modeling
Structured, STRIDE-driven analysis of architecture and data flows to surface design-level weaknesses before a single line of exploit code is written.
Offensive Security — Vulnix0
Continuous DAST, dark web exposure monitoring, and attack-surface testing powered by our offensive security platform, Vulnix0.
Code & Infra Assessment — AquilaX
SAST, software composition analysis, secrets detection, and infrastructure-as-code review delivered with our partner platform, AquilaX.
Phishing Simulation
Realistic, controlled phishing and spear-phishing campaigns that measure and improve the human layer of your defences.
Penetration Testing
Automated scanners flag the obvious stuff and stop there. Our testers — OSCP and CREST CRT certified — manually work through your applications, networks, APIs, and cloud infrastructure the way an attacker actually would, chaining together issues a scanner would score as low-severity on their own.
- Web & mobile application testing (OWASP Top 10, OWASP ASVS)
- External & internal network penetration testing
- API security testing (REST, GraphQL, gRPC)
- Cloud configuration & workload testing (AWS, Azure, GCP)
- Wireless network and physical/red-team engagements on request
- One free retest included within 30 days of the report
A typical single-application engagement runs 5–10 working days on-site or remote, and closes with a technical report plus a 45-minute walkthrough with your engineering team — not just a PDF dropped in your inbox.
{
"finding": "Broken Object Level Authorization",
"category": "API5:2023 - OWASP API Security",
"severity": "High",
"cvss": 8.1,
"endpoint": "GET /api/v1/invoices/{id}",
"impact": "Any authenticated user can view another tenant's invoices",
"remediation":"Enforce tenant-scoped authorization checks server-side",
"status": "retested-fixed"
}
Lowest score, flagged first: Verification. Scores from a first-time assessment at a mid-sized SaaS client — most teams have never formally tested their own test coverage.
OpenSAMM Maturity Assessment
OpenSAMM (the OWASP Software Assurance Maturity Model) assesses how mature your software security practices are — not just your code. We review your organisation across five business functions: Governance, Design, Implementation, Verification, and Operations.
- Interview-driven assessment against 15 SAMM security practices
- Maturity scoring (0–3) per practice, benchmarked against industry peers
- Gap analysis between current and target maturity levels
- Prioritised, phased roadmap your teams can actually execute
- Rerun annually to track movement — most clients gain 0.3–0.5 per function in year one
Threat Modeling
Before we try to break something, we model how it can break. Working from architecture diagrams and data flow, our analysts map trust boundaries and systematically enumerate threats using the STRIDE methodology — Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege.
- Data flow diagram & trust boundary mapping
- STRIDE-based threat enumeration per component
- Attack tree construction for critical assets
- Risk-ranked mitigations mapped to MITRE ATT&CK techniques
- Ideal for new architecture reviews, major features, or M&A due diligence
Offensive Security — Powered by Vulnix0
For continuous, attacker-perspective coverage between formal pentest cycles, we run assessments through Vulnix0, our dedicated offensive security platform. It keeps your attack surface under constant scrutiny rather than a once-a-year snapshot.
- Dynamic Application Security Testing (DAST) of live web applications
- Dark web & leaked-credential exposure monitoring
- Continuous external attack surface discovery and scanning
- Structured penetration testing engagements on demand
- Findings correlated with OneFirewall's Crime Score threat intelligence
Scans run on a rolling weekly schedule by default; new critical findings page your team the same day rather than waiting for the next quarterly review.
Explore Vulnix0 →$ vulnix0 scan --target app.example.com --mode dast [+] Crawling application surface ... 312 endpoints [+] Dark web exposure check ... 2 credential matches found [+] Active DAST pass ... complete Findings: HIGH Reflected XSS on /search?q= MEDIUM Missing rate limiting on /api/login LOW Verbose server banner disclosure # synced with OneFirewall Crime Score engine
$ aquilax scan --repo backend-api --scope sast,sca,secrets,iac [+] SAST ................ 14 findings (2 high) [+] SCA (dependencies) .. 6 vulnerable packages [+] Secrets detection ... 1 exposed API key [+] IaC review (Terraform) 3 misconfigured S3 buckets Summary: 24 findings triaged, remediation PRs suggested
Code & Infrastructure Assessment — Powered by AquilaX
Developed in partnership with AquilaX LTD (UK), our code and infrastructure assessment reviews the software itself and the environment it runs in — before it ever reaches production.
- Static Application Security Testing (SAST) across your codebase
- Software Composition Analysis (SCA) for vulnerable dependencies
- Secrets & credential leakage detection in source and history
- Infrastructure-as-Code review (Terraform, CloudFormation, Kubernetes manifests)
- Cloud & container configuration assessment
Plugs into your existing CI pipeline (GitHub Actions, GitLab CI, Jenkins) so findings show up as PR comments, not a separate portal nobody checks.
Explore AquilaX →Phishing Simulation Campaigns
Technical controls can't stop every attack that targets people directly. Our phishing simulation campaigns test and train your workforce with realistic, controlled scenarios — safely, and with full reporting.
- Realistic phishing & spear-phishing email templates, tailored to your sector
- Credential-harvesting landing page simulations (no data ever stored)
- Click-through, submission, and report-rate tracking per department
- Just-in-time awareness training triggered on click, not a slide deck the following month
- Executive & board-ready reporting with trend-over-time metrics
- Quarterly cadence by default; monthly or continuous on request
Hi,
Our records show your network password expires in a few hours. To avoid being locked out, please verify your account now.
IT Helpdesk
How an Engagement Runs
Every assessment — whatever the discipline — follows the same disciplined lifecycle.
Scoping
Define targets, rules of engagement, and success criteria with your team.
Assessment
Manual testing, maturity interviews, threat modeling workshops, or campaign execution.
Risk Scoring
Every finding is triaged and scored — CVSS, SAMM maturity level, or risk rating.
Reporting
Executive summary plus technical detail, reproduction steps, and remediation guidance.
Retest & Roadmap
Verify fixes and track maturity improvement across subsequent engagements.
Questions We Get Asked
How long does a typical penetration test take?
A single web application or API usually takes 5–10 working days depending on scope and authentication complexity. Network and cloud engagements vary more with the number of in-scope hosts — we'll give you a firm day count during scoping, not a range.
Do you sign an NDA and agree rules of engagement before testing?
Yes, always. Every engagement starts with a mutual NDA and a signed rules-of-engagement document covering scope, testing windows, exclusions, and an emergency contact on both sides in case something needs to stop immediately.
Is retesting included, or is that a separate cost?
One retest of reported findings is included in every pentest and Vulnix0 engagement at no extra cost, as long as it's requested within 30 days of the final report. Retests outside that window are scoped separately.
Can this support our ISO 27001, SOC 2, or PCI DSS requirements?
Yes. Pentest reports are formatted to be handed directly to an auditor, and OpenSAMM assessments map cleanly onto ISO 27001 Annex A and SOC 2 CC-series controls. Tell us which framework you're working toward during scoping and we'll align terminology and evidence accordingly.
Do we need to be a OneFirewall Alliance member to book an assessment?
No. Security assessments are engaged separately from Alliance membership, though members do get priority scheduling and a discount on Vulnix0 and AquilaX continuous-monitoring subscriptions.
Ready to Assess Your Security Posture?
Tell us which discipline you need — pentest, OpenSAMM, threat modeling, Vulnix0 offensive testing, AquilaX code & infra review, or a phishing campaign — and we'll scope an engagement around it.