Skip to content
bughunter.pro
/Request an audit

Who better than an ethical hacker to find your vulnerabilities?

An attacker only needs one flaw. Our job is to find it before they do. We think like them: patient, methodical, quiet. Where automated tools stop, we keep going, uncovering the weaknesses in your system until we reach the one that truly threatens your business. Then, instead of walking away with what we found, we hand you everything you need to fix the vulnerabilities for good.

Adversarial mindset

Real attacker logic. We hunt the path no scanner will ever find.

Real-world rigor

Hands-on experience built on high-traffic platforms and sensitive environments.

Absolute discretion

Strict confidentiality, NDA as standard, encrypted reports if needed.

An audit shaped around your situation.

Whether you're launching a site or looking to secure a service already live, these are the engagements we run most often.

Pre-launch audit

Catch flaws while they still cost a fix, not an incident, before your site or feature ever goes live.

Live production testing

Already online? We test it the way a real attacker would, quietly, and without breaking anything.

API audit

REST, JSON, GraphQL: we make sure every endpoint exposes only what it should, and only to whoever should reach it.

Auth & access review

Who can reach what? We hunt the access that crosses the lines you set: IDOR, privilege escalation, broken permissions.

Second opinion & post-incident

A doubt after an alert or a major change? We confirm what's real, qualify the impact, and document it.

Anything that takes a request, we'll test.

From a brochure site to a complex business platform: any surface reachable from a browser or an API is a potential target, and therefore a candidate for penetration testing.

Websites & web apps Customer portals & client areas Back-offices & admin panels Business platforms WordPress & other CMS Authentication & SSO Roles & permissions Payments & checkout REST / JSON APIs Third-party integrations

The vulnerabilities we go after.

In practice, here are the doors an attacker tries to open. The gist fits in one line for newcomers, and the technical detail is there for experts.

Injections & input

Making the app run what it shouldn't.

XSS
SQL injection
File upload abuse
Path traversal

Access & identity

Seeing or doing what isn't yours.

IDOR / BOLA
Broken access control
Privilege escalation
Broken authentication

API & logic

Bending business rules and authorizations.

API authorization flaws
BFLA
Mass assignment
Business logic flaws

Server & config

Exploiting a setting left open.

SSRF
CSRF
CORS misconfiguration
Information disclosure

A repeatable path from recon to retest.

01

Recon & mapping

We map everything you have exposed, including the subdomains, endpoints and forgotten flows you didn't know were still online.

02

Surface analysis

We learn your roles, trust boundaries and business logic before attacking, to aim precisely rather than broadly.

03

Manual exploitation

Where scanners are blind, we hand-craft attacks and chain weaknesses into real, demonstrable impact.

04

Impact & proof

A reproducible proof of concept: you see exactly what an attacker could reach.

05

Clear reporting

Priorities both leadership and engineers can read, with what to fix and in what order.

06

Retest & close

We re-check every fix ourselves: a flaw is only closed once we've confirmed it.

What you receive after our engagement.

Work your teams, or your providers, can act on immediately, with every finding proven and explained.

Prioritized report

Every flaw ranked by real severity and urgency, so the most dangerous gets fixed first, not the loudest.

Reproducible proof of concept

The exact steps to replay each flaw. No "maybe", no theory, proof you can hand straight to your developers.

Business impact

In plain language: what it exposes, what it could cost, and who is affected. Readable without a security background.

Concrete remediation

Not just "it's broken": how to fix it, step by step, in a way your team can actually apply.

Retest included

Once you've patched, we re-check your fixes. The door is shut, and verified, not assumed.

Debrief & handover

A walkthrough of the report with your team, so the findings are understood and owned, not just delivered.

See what the report looks like

Focused where it counts: web and APIs.

We focus on two surfaces: the web and the APIs, exactly where your customer data, your payments and your access controls live. Depth over breadth: we'd rather know these environments inside out than scan everything at the surface, where the costly vulnerabilities never show.

The web layer

Websites, web apps, customer portals, client areas, back-offices and CMS: the full interface your users and staff touch.

Websites Web apps Portals Client areas Back-offices SPA CMS

The API layer

REST and JSON APIs, authentication, authorization, and the third-party integrations that hold everything together.

REST JSON GraphQL Auth & tokens Webhooks Integrations WebSockets OAuth & OIDC API versioning

Native mobile is outside our scope. For that, we'll happily point you to a trusted specialist.

Proven where the stakes are highest.

Vulnerabilities found, reported and fixed on perimeters where a mistake gets paid for in cash.

French public services (.gouv.fr)

CAC 40 groups

Luxury-industry leaders

French national media

Town halls and local authorities

Active researchers on YesWeHack Intigriti

A few real findings, anonymized and fixed.

Secrets vault An infrastructure secrets vault, unsealed and unauthenticated, on a national public broadcaster: the keys to everything, reachable by anyone.
Critical
Broken access control 152,000 reader profiles at a national daily paper, readable and wipeable in a single request, with no account.
Critical
BOLA Full control of a national newsroom's staff directory: reading, altering, creating and deleting journalist accounts from a key left in the public code.
Critical
Remote code execution Unauthenticated code execution on a server of a major engineering school: a foothold on the whole machine.
Critical
SQL injection The entire database of a press title, 200+ tables of personal data, exportable without a single account.
Critical
Path traversal Arbitrary file write on a town-hall website, chained into an administrator session forged without a password.
Critical
Business logic Premium subscriptions created without paying and without an account, on a national business-news platform.
High
Exposed service A company's video-surveillance system, recorders and live RTSP feeds alike, reachable straight from the internet with no filtering at all.
High

We never disclose a client's name, nor the vulnerabilities found. These examples are rewritten so none of them can be traced back to anyone.

Questions, answered.

Do you sign NDAs?

Yes. Confidentiality is the default, not an upsell. An NDA is signed before any scope is shared, and reporting can be fully encrypted on request.

Will you ever name my organization?

Never. Your identity, your scope and every finding stay strictly between us. Discretion is part of the service.

Do you test mobile applications?

Our focus is the web and APIs. That is where we go deepest and find the highest-impact vulnerabilities. For native mobile, we will gladly refer you to a specialist we trust.

How does an engagement start?

A short scoping conversation, a signed agreement, then a defined testing window ending in a clear, prioritized report.

How long does an engagement take?

It depends on the scope. A focused audit can wrap in a few days. A complex application will take two to three weeks. We align on that during scoping.

How much does an audit cost?

Scoped to what you actually need: pricing depends on the size and complexity of your perimeter. We define it together in a first, no-commitment conversation.

Start with a conversation.

Tell us what you'd like tested. Everything you send is treated as strictly confidential. Based in France, working remotely across Europe and worldwide, in English or French.