Web applications and APIs
Authentication, session and permission handling, business logic, injections, data exposure, REST and GraphQL API security.
services · 01 · core
I look for what an attacker would find on your system, demonstrate it without breaking anything, and explain how to fix it.
Engagements in Caen, Normandy and remotely.
Discuss the scope → or ask to be called back
Authentication, session and permission handling, business logic, injections, data exposure, REST and GraphQL API security.
Local storage, server communications, client-side controls, and the API the app relies on.
Cloud account configuration, identity and access management, service exposure, images and orchestrators.
Server and workstation hardening, permissions and privilege escalation, exposed services, compromise paths.
Connected and embedded devices, firmware analysis and reverse engineering. The ground my open-source projects are built on.
What an attacker learns about you from open sources: exposure, leaks, external attack surface.
These tests measure how your organisation reacts to a realistic attack: a booby-trapped email, or an attempt to access your premises. They require a stricter framework than technical tests.
No test is carried out without written authorisation and a validated scope (rules of engagement).
Accessing a computer system without authorisation is an offence (articles 323-1 et seq. of the French Criminal Code), even with good intentions.
If you ask me to test a system you do not own, the agreement of its owner or host is also required.
Data collected during the engagement is encrypted. Operational data is deleted at the end; only the report and necessary evidence are kept, encrypted, for the duration set in the contract.
Denial-of-service testing is not part of the offering.
A system to test? Let's talk scope and schedule. Single day rate of €1,100 (excl. VAT).
Reply within a few business days, no commitment.