Web & API security services.
We are security researchers based in France. Our job is to attack your applications before someone else does it for the wrong reasons, then hand you everything you need to fix what we found. These are the engagements we run most often.
Five ways to get your systems tested.
Every one of them rests on manual research. An automated scanner only finds what has already been catalogued. The flaws that cost real money require understanding your business logic, and that part does not automate. These engagements get booked when you need them: before a launch, after a rebuild, or to qualify an alert nobody can settle.
Web penetration testing
Your application is live. We test it the way a real attacker would: hunting for the path nobody planned for, without breaking anything and without your users noticing.
Read moreAPI security audit
REST, JSON, GraphQL. An API has no interface to lie to you with: it answers exactly what it is asked. What remains is checking it only answers the right people.
Read moreWordPress penetration testing
Plugins, themes, roles, admin surface. The WordPress core is solid, but what gets stacked on top of it is far less so, and that is almost always where hackers get in.
Read moreWebsite security audit
Brochure site, online store or CMS. Most of what hits a public website is aimed at nobody in particular: it sweeps, it finds, it comes back.
Read moreAuthentication and access control
Who can actually do what. IDOR, privilege escalation, tenant isolation: the most common flaw there is, and the one no tool can see.
Read moreWhich one is yours?
It is not your industry that decides which engagement fits, it is where your project stands. Three questions settle it.
Is the application already live?
If it is, you want web penetration testing: we work on the real system, with real data and real behaviour, which no staging environment reproduces faithfully. If it is not, we scope a pre-launch audit against a representative staging copy.
Where does your sensitive data live?
If most of the business logic sits behind endpoints consumed by a JavaScript front end or a mobile app, you want an API security audit. That is where we find the most serious flaws today, because access controls there are often assumed rather than verified.
What is the site running on?
If the answer is WordPress, the ways in are specific enough to deserve their own approach, which is what WordPress penetration testing covers.
You do not have to work this out alone. Describe your situation and we will tell you what makes sense, including when the answer is "you do not need us yet".
What never changes.
- A signed testing agreement and NDA before any access at all.
- A defined testing window, known only to you if that is what you want.
- A report prioritized by real severity, not by theoretical score.
- A reproducible proof of concept for every finding.
- A retest of every fix, included, at no extra charge.
- A debrief with your technical team, in plain language.
Start with a conversation.
Tell us what you would like tested. The first conversation carries no commitment, and everything you send is treated as strictly confidential. Based in France, working remotely across Europe and worldwide, in English or French.