Give the requester useful evidence.
Align the scope to an audit or customer requirement. Record what was tested, what was found and what the result does not establish.
An audit to prepare for. A customer to reassure. A product to launch. Get a human-led penetration test that turns technical risk into a clear plan of action.
Web · Mobile · API · Network · Cloud · AI
Two choices. A useful scope, not a guessed price.
Choose a reason and a system to see the suggested scope. No email needed.
Scope and fee confirmed before testing.
Human-led testing.
Manually verified findings.
Align the scope to an audit or customer requirement. Record what was tested, what was found and what the result does not establish.
Test the sign-in, data and business workflows that matter before a new feature becomes part of production.
Get reproducible evidence and remediation priorities, then confirm the agreed fixes with a focused retest.
One application or a connected estate. Choose a focus, then agree how the boundaries fit together.
Authenticated testing of SaaS products and web applications across your agreed roles.
Explore testing 02Security testing for iOS and Android apps, from local data to the backend calls in scope.
Explore testing 03REST and GraphQL testing focused on object-level access and token boundaries.
Explore testing 04External and internal testing with explicit host ranges and segmentation goals.
Explore testing 05Controlled attack-path testing across cloud identities, workloads and data access.
Explore testing 06Testing for AI applications, retrieval systems and agents, focused on data boundaries.
Explore AI securitySystems, roles and objectives. Written authorisation, safe test windows and a stop-test contact.
Manual investigation supported by tools. Controlled evidence of impact, with urgent findings raised promptly.
A concise risk summary and technical detail your engineers can reproduce and act on.
A focused retest of agreed findings, recording resolved, partial and outstanding items. Terms set in the scope.
Understand the risk without losing the technical evidence. We separate confirmed findings, limitations and remediation status.
Download the illustrative report (PDF)
A 19-page illustrative example built from synthetic findings. Not a client report, and no real company, person or IP appears in it.
Explore what a useful report containsA test report supports assurance. It is not a certificate of security or a promise of audit acceptance.
Contents overview, not a sample client report.
OSCP-certified testers combine methodical investigation with practical engineering context. We use automation where it helps and verify findings before reporting them.
From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.
Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.
It can provide useful evidence, but acceptance depends on the requester’s requirements. Send us their exact wording before booking. Scope, credential and retest requirements all matter. A test does not itself confer SOC 2 or ISO 27001 certification.
Both have a role. Tools help with discovery and coverage; testers investigate business logic, check boundaries and manually validate findings. The result is an assessment, not an unreviewed scanner export.
Production testing needs explicit written permission, agreed techniques, safe test data and an escalation plan. We record constraints and stop if the agreed safety conditions are not met. Destructive testing and denial of service are excluded by default.
Our testers hold OSCP, OSWE, OSCE and OSWP from OffSec. The list also includes CREST Registered Tester, eCPPT v2 and Zero-Point Red Team Operator. Cloud and detection work adds AWS and CrowdStrike certifications. Every acronym is expanded on our about page.
No. Sorami Consulting Pty Ltd is not a CREST member company, and CREST accreditation is a company status we do not hold. Our testers hold individual CREST Registered Tester certification, which is a different thing. If your procurement form requires a CREST member company, tell us on the scoping call and we will confirm in writing that we are not the right firm.
Only your email is required. Scope and fee are agreed in writing.
Last reviewed: