← All services Our services

Penetration testing and security testing

I attack your own software with your written permission, looking for what an attacker would find: logging in without the right password, reaching another customer's data, changing an amount in an order. Whatever works, you get on paper with the evidence attached and with the check that proves later on that it is really closed.

A pen test is not a scan with a nicer name. The scan finds what there is to find; the work after that is what a machine does not do: verifying findings so you are not handed false alarms, chaining separate weaknesses into one attack route, and judging what that means for your business. I test in three variants that differ in what you hand over up front: only your web address, a test account as well, or the source code as well. The more I see, the more there is to test — which is exactly why a real attacker signs up for an account too.

What you get

A report written to be read by someone who is not a hacker Per finding: what it is, where it sits, how serious it is and what it means for your business Step by step how to reproduce it yourself, with screenshots and network captures as evidence A retest criterion per finding, so you can demonstrate the hole is closed One retest after the fix On request mapped to OWASP, ISO 27001, NIS2 and GDPR for your audit file

Priced per case. The difference is the size of the application and what you hand over: only a web address, a test account as well, or the source code as well. We set the scope in the discovery call, after which you get a fixed price, and permission is put in writing before anything runs.

Does your AI fall under the EU AI Act?

Free · 10 questions · 3 minutes

Start the quickscan →
Penetration testing and security testing

Questions and answers about this service

What is a penetration test?

A penetration test is an attack on your own software, carried out with your written permission, to find what an attacker would find. Unlike an automated scan, the findings are verified, separate weaknesses are chained into an attack path and the impact on your business is assessed.

Who is a penetration test for?

For organisations with a website, webshop, customer portal, integrations or their own software that holds customer data. Also for anyone who has to demonstrate that security is in order, for example for NIS2 or ISO 27001: the findings can be mapped to those standards.

What is the difference between black-box, grey-box and white-box?

It is about what the tester gets up front. Black-box means only your web address, exactly what an outsider has. Grey-box adds a test account, so everything behind the login gets tested; that delivers the most value per hour. White-box adds the source code, so leftover keys and outdated components with known vulnerabilities become visible.

What gets tested in a penetration test?

The application and its integrations against the OWASP categories, the login and permissions per role, whether someone can reach another customer's data, servers and open ports, the settings of the encrypted connection, third-party components with known vulnerabilities and AI features: can a user make an assistant ignore its instructions or reveal data? Mobile apps are a separate track.

How does a penetration test work?

In the discovery call we define the scope. Before the first scan we record the permission in writing, with domains, time window and contact person. Then comes the test and a report with evidence, reproduction steps and a retest criterion for every finding. After your fix there is one retest. If you want, there is a fixed rhythm: a light scan every month and a deep one every quarter.

What does a penetration test not promise?

That everything will be found. That is why the report also states what was not tested and where the test stopped. Automated testing does not replace a specialist who spends days on one application. A red team with weeks of stealthy intrusion and deceiving staff is not part of it. Mapping to ISO 27001 is not an audit and not a certificate.

Thinking along, arranging it, staying inside the law

Three things that don't fit in a service list, but that decide how working with me feels.

I think along with you

You're not hiring a pair of hands that builds whatever the brief says. If I think your question isn't your real problem, I'll say so. Often there's a simpler or cheaper route, and sometimes the answer is that you shouldn't build this yet. Sparring over that choice is part of the work.

You don't have to figure it out

I run the whole track: choice of technology, the build, integrations with your existing systems, testing with real cases, explaining it to your team and maintenance afterwards. One point of contact, and one person responsible when something breaks. No vendors pointing at each other.

Compliant, and provably so

Everything I build has to survive current legislation: GDPR, the EU AI Act and the Data Act. That means agreeing up front which data the system may see, where it is processed, retention periods, a data processing agreement and a log of what the system did. So you can explain it when somebody asks.

Other services

AI voice agents and telephony

An agent that answers the phone after hours, at peak moments and when everyone is already on a call. It recognises why someone is calling, books an appointment in your calendar, transfers when unsure and emails you the rest.

View this service →

Process automation

The work nobody enjoys: retyping invoices, moving data from system A to system B, producing the same report every Monday. I map the steps and build the chain that runs without you.

View this service →

Custom software, SaaS & AI assistants

For when off-the-shelf doesn't fit: a portal, an internal tool, or an assistant that answers from your own documents and data. Built around your way of working, not a vendor's.

View this service →

AI audit & AI training

The cheapest way to start. I come to you, and afterwards you get a report with the processes that return the most, what each costs, what it saves and what goes wrong if you approach it badly. I also run AI training for teams: what the technology can and cannot do, how to use it safely, and where the gains sit in your own work.

View this service →

GDPR & privacy in order

Mapping what happens to personal data and delivering the documents you need to be able to show: a record of processing activities, a DPIA where one is required, processor agreements and a working method for data breaches and data subject requests.

View this service →

EU AI Act: from scan to dossier

For anyone using AI or shipping AI inside their own product. We determine per system which risk category it falls into, which role you hold and what that means in obligations. Then we build the dossier that goes with it.

View this service →

European software regulation

GDPR and the AI Act are not the only laws that touch your software. Depending on what you build and for whom, NIS2, the Cyber Resilience Act, the accessibility directives, the Data Act or DORA apply too. I work out which ones apply to you and what has to happen next.

View this service →

Ready to see what's being left on the table?

Book a free thirty-minute call. You'll get an honest answer, even when that answer is “don't do this yet”.

Book your free intro call → Free · 30 minutes · no obligations