Penetration
testing
Understand how someone could access your data or misuse your application. We test the agreed scope, explain the findings and can carry out the fixes and retesting.
A user can open another client’s file
A signed-in user changes the file reference in a request. The application returns a document belonging to a different account.
Cover the ways your system is used
We tailor the test to the application, its users and the data it holds. Source access, test environments and any production testing are agreed before work starts.
Web applications
Authentication, sessions, roles, file access and business logic. Check whether people can read records or take actions beyond their permissions.
APIs and integrations
Account boundaries, token permissions, exposed endpoints and connected systems. Agree which third-party services are inside the authorised scope.
AI and agent workflows
Prompt injection, data disclosure, unsafe tool use and approval bypasses. Test the permissions and actions around the model as well as its responses.
Prompt-injection testing ↗From authorised test to verified fix
Scope and access
Named systems, test accounts, permitted methods, timing and stop conditions. Written authorisation before testing.
Test and validate
Combine manual investigation and appropriate tooling. Check findings and record reproducible evidence.
Fix and retest
Your team can implement the fixes, or we can include remediation. Retest the original issue against the changed system.
Report the result
Provide coverage, findings and retest outcomes, including remaining issues and anything outside the test.
A report you can act on
Agree the audience and reporting requirements at the start, whether the report is for developers, an IT lead or procurement.
- Systems, dates and methods tested
- Validated findings and business impact
- Reproduction steps and remediation guidance
- Retest results and remaining issues
- Coverage limits and recommended next work
AI-assisted security review
Vu has OpenAI Trusted Access for Cyber, with access to specialist Codex cybersecurity capabilities. We can use these for source review and vulnerability investigation, alongside manual validation.
We agree how client code and test data may be handled before using external tools. Findings need evidence, and fixes need retesting.
Independent assessment when needed
If your buyer or insurer requires an independent tester or a particular accreditation, send us the requirement. We can arrange a suitable external assessment within the agreed engagement and handle the remediation.
We identify the testing provider and their credentials in the scope. OpenAI access is a tooling capability, separate from accreditation.
Can you test software another supplier built?
Yes. We agree the authorisation, available access and scope with you. You can ask us to report to your existing development team or include implementation of the fixes in our engagement.
Can testing include production?
It can, where it is needed and authorised. We agree safeguards, timing and stop conditions with the system owner. A representative test environment and synthetic records are useful for work that could affect availability or data.
How do you price the work?
We agree a fixed fee for the defined scope before starting. The proposal identifies testing, reporting, any remediation and retesting, so you can see what is included. Extra systems or assessment requirements are priced before they are added.
Tell us what needs testing
Send the system overview and any security questionnaire, deadline or independent-testing requirement. We’ll work through the scope with your technical lead.
Please keep credentials and sensitive test data out of the initial enquiry.
Our security practices and certification ↗