Skip to main content
Success
Security & governance

Penetration
testing

Understand how someone could access your data or misuse your application. We test the agreed scope, explain the findings and can carry out the fixes and retesting.

Example findingIllustrative, fictional system
Access control

A user can open another client’s file

A signed-in user changes the file reference in a request. The application returns a document belonging to a different account.

FindingAccount check missing
FixEnforce account ownership
RetestRequest refused
Your report records the evidence, affected scope and result after remediation.
Agree what needs testing

Cover the ways your system is used

We tailor the test to the application, its users and the data it holds. Source access, test environments and any production testing are agreed before work starts.

Web applications

Authentication, sessions, roles, file access and business logic. Check whether people can read records or take actions beyond their permissions.

APIs and integrations

Account boundaries, token permissions, exposed endpoints and connected systems. Agree which third-party services are inside the authorised scope.

AI and agent workflows

Prompt injection, data disclosure, unsafe tool use and approval bypasses. Test the permissions and actions around the model as well as its responses.

Prompt-injection testing ↗

From authorised test to verified fix

Agree

Scope and access

Named systems, test accounts, permitted methods, timing and stop conditions. Written authorisation before testing.

Investigate

Test and validate

Combine manual investigation and appropriate tooling. Check findings and record reproducible evidence.

Resolve

Fix and retest

Your team can implement the fixes, or we can include remediation. Retest the original issue against the changed system.

Review

Report the result

Provide coverage, findings and retest outcomes, including remaining issues and anything outside the test.

Evidence for your team

A report you can act on

Agree the audience and reporting requirements at the start, whether the report is for developers, an IT lead or procurement.

  • Systems, dates and methods tested
  • Validated findings and business impact
  • Reproduction steps and remediation guidance
  • Retest results and remaining issues
  • Coverage limits and recommended next work
Specialist tooling

AI-assisted security review

Vu has OpenAI Trusted Access for Cyber, with access to specialist Codex cybersecurity capabilities. We can use these for source review and vulnerability investigation, alongside manual validation.

We agree how client code and test data may be handled before using external tools. Findings need evidence, and fixes need retesting.

Procurement requirements

Independent assessment when needed

If your buyer or insurer requires an independent tester or a particular accreditation, send us the requirement. We can arrange a suitable external assessment within the agreed engagement and handle the remediation.

We identify the testing provider and their credentials in the scope. OpenAI access is a tooling capability, separate from accreditation.

Can you test software another supplier built?

Yes. We agree the authorisation, available access and scope with you. You can ask us to report to your existing development team or include implementation of the fixes in our engagement.

Can testing include production?

It can, where it is needed and authorised. We agree safeguards, timing and stop conditions with the system owner. A representative test environment and synthetic records are useful for work that could affect availability or data.

How do you price the work?

We agree a fixed fee for the defined scope before starting. The proposal identifies testing, reporting, any remediation and retesting, so you can see what is included. Extra systems or assessment requirements are priced before they are added.

Tell us what needs testing

Send the system overview and any security questionnaire, deadline or independent-testing requirement. We’ll work through the scope with your technical lead.

Please keep credentials and sensitive test data out of the initial enquiry.

Our security practices and certification ↗
Message us on WhatsApp