What we deliver

Scope of work

Every engagement is scoped in writing before it starts. A typical engagement includes:

  • Attack-surface mapping across applications, APIs, cloud and identity
  • Web application and API penetration testing against the OWASP Top 10 and OWASP API Security Top 10
  • Business-logic, authorisation (BOLA, BFLA, IDOR) and session testing that scanners miss
  • Cloud configuration and identity review across Azure, AWS and GCP
  • Threat modelling with STRIDE, and with agentic frameworks for AI-enabled systems
  • Vulnerability chain analysis showing how low-severity issues combine into real impact
  • Exploitability-ranked report, executive summary and a remediation roadmap, with retesting of fixed findings

What you get

Outcomes

  • A prioritised list of what to fix first, written for both engineers and leadership
  • Evidence your auditors, customers and insurers can rely on
  • Fewer surprises at go-live, because testing happens before attackers do

Track record

Experience behind it

  • Certified Ethical Hacker (CEH v13), EC-Council
  • Offensive research across heap exploitation, ROP and JOP chaining, ASLR and PIE defeat, and sandbox escape, grounded in real CVE families
  • Published root-cause analysis of the Ivanti EPMM pre-authentication RCE (CVE-2026-1281, CVE-2026-1340)
  • Secure-by-design API architecture delivered to Singapore IM8 and OWASP requirements for a central-bank platform

Technologies and frameworks

  • Burp Suite
  • OWASP ZAP
  • Nmap
  • Metasploit
  • SQLMap
  • Nikto
  • Hydra
  • Wireshark
  • Semgrep
  • STRIDE

FAQ

Common questions

Something else on your mind? Ask us directly.

What does a LogicSense penetration test cover?

Scope is agreed up front and usually covers web applications, APIs, cloud configuration and identity. We test against the OWASP Top 10 and OWASP API Security Top 10, look specifically for business-logic and authorisation flaws, and show how individual weaknesses chain into real impact.

How are findings prioritised?

By exploitability and business impact, not by raw CVSS score alone. A medium-severity issue that is reachable from the internet and chains into data access is ranked above a high-severity issue that cannot be reached.

Who performs the testing?

Testing is led by a Certified Ethical Hacker with more than sixteen years of engineering and architecture experience who also builds security products. The same person scopes the work, performs it and walks you through the report.

Related services

Often combined with

Have a system to build, modernise or secure?

Tell us where things stand today. The first conversation is free, and you will leave it with an honest view of the work involved.