SysAlbania offensive security
We break it before
someone else does
Penetration testing and incident response for teams that ship fast. Fixed scope, evidence in every finding, retest included.
What we do
Four engagement types. Each one is fixed scope and fixed price, quoted before work starts.
How an engagement runs
No surprises. You know the scope, the window and the price before we start.
- 01
Scope
We agree targets, rules of engagement and a testing window in writing before anything is touched.
- 02
Test
Manual testing against the agreed surface, backed by tooling. You get a same-day call if we find something critical.
- 03
Report
Every finding carries reproduction steps, evidence and a CVSS rating, written so a developer can act on it.
- 04
Retest
Once you have fixed the findings we verify each one and reissue the report. Included, not billed separately.
What lands in your inbox
A report your developers can act on, not a tool dump with a logo on the cover.
- Executive summary written for non-technical stakeholders
- Every finding with reproduction steps, evidence and CVSS rating
- Same-day disclosure call if anything critical surfaces mid-test
- Remediation retest and a reissued report, included
Common questions
How long does a penetration test take?
A typical web application test runs five to ten working days including reporting. Scope drives the number, and we confirm it in writing before starting.
Do you need production access?
Not usually. Most tests run against a staging environment that mirrors production. Where production testing is genuinely required we agree a window and a rollback plan first.
What do we receive at the end?
A written report with an executive summary, every finding with reproduction steps and CVSS rating, and a remediation retest once fixes are in place.
Is retesting included?
Yes. Verifying that a fix actually works is part of the engagement, not a separate invoice.
Find out what an attacker would find
Tell us the target and the deadline. You get a fixed quote within two working days.