Offensive testing
A list of 4,000 findings is not a security test.
Vulnerability assessment asks what weaknesses exist. Penetration testing asks which of them an attacker could actually use, and how far they would get. Automated scanners are good at the first and useless at the second. Our testers verify findings manually, chain small weaknesses the way a real intruder would, and hand you a fix list ordered by business impact — plus a free retest once your team has done the work.

- OWASP + PTES
- Recognised testing methodology
- Every finding
- Manually verified before it is reported
- Free retest
- Included after you remediate
Sound familiar?
If two of these describe your week, this is the service that fixes it.
An auditor or a customer has asked for a penetration test and nobody knows what a good one looks like.
Your last report was a scanner export with no proof anything was exploitable.
Fixes were never verified, so the same findings come back next year.
What the service covers
How the work is actually done, day to day.
Network and infrastructure
We test your internet-facing perimeter, then what an attacker could do once inside: moving between systems, abusing Active Directory, and crossing network segments that were supposed to be separate.
Applications and APIs
Web, mobile and API testing covering login, permissions, injection and data exposure — including business logic flaws, like changing a price at checkout, that no scanner will ever find.
Cloud configuration review
Most cloud incidents are misconfigurations, not exploits. We review identity permissions, storage exposure, key handling and network rules across AWS, Azure and GCP.
Testing your people
Optional phishing and phone-based simulations that show how your staff respond under pressure and tell you exactly which teams need training first.
What you receive
Documents you can hand to an auditor.
- Scope document and written rules of engagement
- Executive summary that a non-technical board can act on
- Technical findings with screenshots and steps to reproduce
- Fix roadmap ordered by risk and effort
- Retest report and signed assessment letter
Platforms we work with
Fluent in the tools, loyal to none of them.
If you already hold licences, we operate them — no resale margin, no forced migration. When a change genuinely closes a gap or saves money, you see both cost models side by side before anyone recommends anything.
Onboarding
How vapt goes live.
- 01
A 45-minute conversation
What you run, what worries you, and what a bad week has already cost you. No slides and no product pitch — we are working out whether we can genuinely help.
- 02
Posture assessment
We examine the estate, compare it against a recognised framework and hand you a prioritised list of gaps. The report is yours to keep whether or not you buy anything.
- 03
Onboarding and a rehearsal
Log sources, agents, access and escalation contacts are agreed, then we run a live drill of a real incident before we call the service live. Untested escalation paths are decoration.
- 04
Steady-state operations
Monitoring, response and reporting run to a written SLA, with a quarterly review that changes the plan whenever your business changes.
Questions
What buyers ask about vapt.
Pairs well with
All servicesSOC as a Service
A team of analysts watching your systems every hour of the day, deciding which alerts are real and acting on them.
02NOC as a Service
Continuous monitoring of networks, servers and applications so faults are caught and fixed before your users notice.
03Data Loss Prevention
Controls across laptops, email, network and cloud apps that spot sensitive data leaving and stop it in the moment.
Hand vapt to people who do this daily.
Tell us how big the estate is and what deadline you are working to. Within three business days you will have a scope, a timeline and a flat monthly number — no discovery fee to get there.
