Skip to content
Pentesys
Pentesting / PTaaS

Human-ledpenetrationtesting,deliveredcontinuously

CREST-aligned testing across networks, applications, cloud, mobile and APIs — scoped properly, tested manually and delivered through the Mirage Portal rather than a PDF at the end.

Mirage ValidatePowered by Mirage Validate

A penetration test should tell you what an attacker could actually achieve in your environment — not simply list what a tool found. Our consultants chain weaknesses, abuse business logic and test the paths automation cannot reach, then explain the impact in terms your stakeholders understand.

Testing is delivered as a service. Findings appear in the Mirage Portal as they are confirmed, so remediation can start on day two rather than three weeks later, and retesting is built into the engagement rather than sold as an extra.

Assessment types

Every test type, covered by experts

Choose the assessments that match your estate — or let us scope a programme that combines several.

Web Application Testing

Deep manual testing of websites, single-page apps and admin portals against OWASP Top 10 and business-logic abuse.

API Testing

REST, GraphQL and SOAP API assessment covering authentication, authorisation, mass assignment and data exposure.

Mobile Application Testing

iOS and Android app testing for insecure storage, reverse engineering, transport security and platform permission abuse.

External Infrastructure Testing

Internet-facing network and service assessment from an attacker perspective, with no prior access.

Internal Infrastructure Testing

Network segmentation, Active Directory and privilege escalation paths assessed from an assumed-breach position.

Cloud Configuration Review

AWS, Azure and GCP assessment of IAM, storage, networking and logging controls against real-world attack paths.

Wireless & Segmentation Testing

Wi-Fi and guest network assessment plus verification that VLANs and segmentation actually contain lateral movement.

Build & Device Hardening Review

Workstation, server and embedded device configuration review against CIS benchmarks and your own policy.

Thick Client Testing

Desktop application assessment covering local storage, update mechanisms, inter-process communication and backend integration.

Social Engineering

Phishing, vishing and pretexting campaigns that measure human resilience and improve awareness training.

Capabilities

What's included in Penetration Testing

Everything below is delivered and tracked through the Mirage Portal.

20+ assessment types

Web, API, mobile, external and internal network, cloud, build review, wireless, IoT, thick client and social engineering.

Manual exploitation

Consultants validate and chain findings by hand, demonstrating real impact rather than theoretical severity.

Live findings

Critical issues are published to the portal and flagged to your team as soon as they are confirmed, not held back for the report.

CVSS, CWE and CVE mapping

Every finding carries a CVSS v3.1 vector, CWE classification and CVE references where applicable.

Free retesting

Remediation is verified and findings are closed with evidence, giving you a clean, auditable trail.

Credit-based flexibility

Buy pre-approved credits and draw down testing when you need it, at a discounted rate versus ad-hoc engagements.

Coverage

Scope and depth

Application testing

  • Web application and single-page app testing
  • REST, GraphQL and SOAP API testing
  • Mobile application testing (iOS and Android)
  • Thick client and desktop application testing
  • Authentication, authorisation and business logic abuse
  • Source-assisted and grey-box review

Infrastructure and cloud

  • External and internal network penetration testing
  • Active Directory and privilege escalation paths
  • Cloud configuration review (AWS, Azure, GCP)
  • Build and device hardening reviews
  • Wireless and segmentation testing
  • IoT and embedded device assessment
How it works

Our delivery process

A consistent, transparent methodology from first conversation to verified remediation.

  1. 01

    Scope

    We define targets, test types, rules of engagement and timing with your team — no guesswork, no scope creep.

  2. 02

    Reconnaissance

    Mapping, enumeration and automated coverage establish the baseline for manual work.

  3. 03

    Manual testing

    Consultants test methodically against OWASP, PTES and CREST-aligned methodology, chaining issues where possible.

  4. 04

    Report

    Findings are documented with evidence, reproduction steps, CVSS scoring and prioritised remediation advice.

  5. 05

    Retest

    Once fixes are in place we verify them and close findings with evidence in the portal.

What you receive

  • Technical report with full reproduction steps and evidence
  • Executive summary written for non-technical stakeholders
  • Findings tracked live in the Mirage Portal with status workflow
  • Remediation guidance per finding, prioritised by business impact
  • Retest report and certificate of testing for clients and auditors

Business outcomes

  • Clear, evidenced view of exploitable risk
  • Faster remediation through live findings and portal workflow
  • Assurance artefacts for customers, auditors and insurers
  • A repeatable annual or continuous testing programme
FAQs

Common questions

How much notice do you need?

Typical lead time is one to two weeks. Credit holders can usually be booked faster.

Is retesting included?

Yes. Verification of remediated findings is included within the engagement window.

Do you provide a certificate?

Yes — we issue a certificate of testing suitable for client, supply-chain and insurance requests.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.