Connect and modernize systems

Security Audit & Penetration Testing. Vulnerabilities are named, prioritised and fixable.

Comprehensive security analysis of your systems

  1. Workshop
  2. Setup
  3. Sprint
  4. Build & Support

Fixed price after scoping · proposal within 48 h

Reviewed: September 2026

Security Audit & Penetration Testing
Security Audit & Penetration Testing
Security Audit & Penetration Testing

A security audit with penetration testing is the systematic examination of applications, interfaces and infrastructure for exploitable vulnerabilities; the result is a risk-prioritised findings report with remediation measures.

Security vulnerabilities can be existential threats. We conduct comprehensive security audits – from code reviews through penetration testing to compliance checks (GDPR, ISO 27001). You receive a detailed report of all found vulnerabilities, prioritized by risk, with concrete action recommendations and optional support with remediation. We test web applications, APIs, cloud infrastructures, and mobile apps. If your company falls under NIS2 — the German implementing act has applied since 6 December 2025 without a transition period, and the deadline for registering with the BSI has also passed — we review risk management, reporting paths and evidence duties alongside the technical audit, and tell you what is already provable and what remains organisational work.

Who it's for

Essential for companies that process sensitive data, must meet compliance requirements, or want to secure their systems before market launch. Particularly important for FinTech, HealthTech, and e-commerce.

Key Features

  • Thorough & comprehensive
  • Compliance ready
  • Actionable
  • Priority-based roadmap
  • OWASP Top 10
  • Pentest
  • ISO 27001
  • Compliance

We select the optimal tech stack for your specific requirements

How we work on it

  1. Workshop
  2. Setup
  3. Sprint
  4. Build & Support
(01)

Workshop

A facilitated session that ends with a ranked list of your projects.

½–2 days · three fixed prices
(02)

Setup

We set up one clearly bounded system and hand it over ready to use.

1–2 weeks · fixed price after scoping

Included

(01)

Definition of scope, test windows and contacts

(02)

Testing of web applications and APIs against the OWASP Top 10:2025

(03)

Penetration test and targeted code review of critical components

(04)

Findings report prioritised by risk, with concrete measures

(05)

Closing session with your team

Not included

(01)

Certification (e.g. ISO 27001): we prepare you, but do not certify

(02)

Fixing the findings (on request, separately after scoping)

(03)

Legal advice on NIS2 or GDPR

How it runs

(01)

Scoping workshop

We define systems, test depth and test windows and agree in writing what may be tested.

prep
(02)

Testing

Automated scans, manual tests and code review; we report critical findings immediately, not only in the report.

W1
(03)

Report & measures

Prioritised findings report, closing session and remediation plan; a retest after fixing is available.

W2
(01)What is the difference between a vulnerability scan and a penetration test?
A scan finds known vulnerabilities automatically. In a penetration test we additionally try, by hand, to chain and exploit vulnerabilities the way an attacker would. We use both.
(02)Will the audit disrupt our operations?
We agree test depth and test windows in writing beforehand. Risky tests are preferably run against a staging environment or closely coordinated with your team.
(03)Do we receive a certificate?
No, we do not certify. Our report documents scope, findings and measures and can serve as evidence for customers and auditors or as part of your NIS2 obligations.
(04)Do you also fix the vulnerabilities found?
On request, yes, as a separate engagement after scoping. Alternatively your team implements the measures and we check in a retest whether they work.
(05)What does a security audit cost?
Fixed price after scoping, quote within 48 hours. The effort depends mainly on the number and size of the systems tested.

Ready for your project?

Talk to us for 30 minutes with no obligation, or write to us directly.

Fixed price after scoping · proposal within 48 h