Your app keeps shipping.
Your pentest tests yesterday's app.

A standing pentest on your external web and API surface: after every release, human-verified, signed report with NIS2 / ISO 27001-ready evidence, one flat annual fee.

every release

retested after you ship, no per-scan billing

100% PoC

every finding with a working PoC

NIS2 · ISO 27001

signed report + evidence mapping, included, not certified

Startups from pre-revenue to Series A that ship monthly+ and need current, signed evidence for the first enterprise questionnaire, a SOC 2, or a diligence round; the standing hunt is your external CISO on a flat fee. Teams that changed little but got their customer's NIS2 questionnaire start with the one-off audit and add continuous coverage later. When the report is asked for, you hand over one that is days old, not months.

How the hunt runs

01

In writing, before the hunt starts.

Hosts, app, API, auth roles: the exact scope sits in a signed authorization and rules of engagement, before the first probe. What isn't in it is never touched.

authorization · rules of engagementsigned
Rules of Engagementacme.dev
  • Your domains
  • Your API
  • Roles in scope
  • Not allowed
  • Emergency stop
S. Abis — Rheono
signed · in writing

This is your authorization: what the hunt may touch. What isn't listed is never touched.

02

The fleet reads your surface.

From the outside, the agent fleet maps every host and endpoint, around the clock, without flooding your logs. What changes is known before an attacker uses it.

surface · livemapping

runs 24/7 — changes are noticed

This is what attackers could see from outside. The fleet maps it continuously, before anyone else uses it.

03

One finding. Proven once.

The hunt flags a signal. Every finding is proven with a working PoC and validated by a named researcher before it lands. Unproven, not reported.

hunt · signalsignal
HIGHunchecked admin access
ProvenPoC: session-fixation — reproducible
Validated by a humanCVSS 8.6

No alarm without proof: every finding ships with a working PoC, and is checked by a named researcher.

04

A report that never goes stale.

CVSS plus NIS2 / ISO 27001 mapping, signed, prioritized at the root. Every release is retested; the retest is the default, not an extra.

report · standingfiled
Signed report — acme.dev2026
  • Finding
  • Compliance
  • Remediation
S. Abis — Rheono
report filed

Retestrelease 2.41 → fix verified ✓

A standing document with a signature: the one you hand to an auditor. Retested after every release.

Human judgment × model scale.

A named researcher makes the calls. The agent fleet maps, follows paths, correlates. Nothing reaches your report that a human has not executed himself.

The researcher

  • DirectsChooses target and tactics
  • VerifiesEvery PoC, himself
  • AssessesMeasures business impact
proven attack paths

The agent fleet

  • ExploitsFinds possibilities
  • TracesFollows complex paths
  • CorrelatesKeeps system-wide context

From the facade to the critical asset.

We work like a real attacker: from the outside, on your authorized surface. We report only what we can prove.

Stage 01

External surface

We test for

  • Web apps and APIs, exposed services
  • Authentication and authorization
  • Subdomains, endpoints, integration APIs
  • Dependencies and known vulnerabilities
  • Initial-access paths

We map your authorized internet-facing surface and exploit what we find to establish a real foothold.

Stage 02

Attack paths to critical assets

We assess

  • Business logic: IDOR, authz, race conditions
  • Access to other users' data
  • Payment and checkout flows
  • Privilege escalation within the agreed scope
  • Controlled data-exfiltration demonstration

From the foothold we test how far an attacker gets: to the assets that actually matter to you.

Two doors. One pricing principle.

One report or the standing hunt. Flat prices, in writing, no per-scan billing.

  • continuous

    The standing hunt

    Your external CISO on one flat annual fee: every release retested, the report stays current. The fee does not grow with your release count.

  • one-off

    The deep audit

    A deep snapshot of your web app and API in 3–5 days: signed NIS2 / ISO 27001 report, PoC per finding, one retest included.

  • optional

    Code-assisted

    Repo access: every release diff read for data-flow issues. File:line + PoC, not scanner output.

  • included

    NIS2 · ISO 27001 evidence

    The signed report as a compliance artifact: PAdES-B-T + qualified timestamp, evidence mapping. No extra cost.

The same engine hunts live bounty programs.

This pipeline hunts live bug-bounty programs every day; your hunt runs on the same one. Full report list on request.

Vercel
Zooplus
Exness
Crypto.com
fintechSaaSe-commerceaerospacecrypto
redacted
F-014CRITICAL · CVSS 9.1fixed in one release · bounty paid

IDOR: sequential order IDs expose other customers' full order history

Order ID comes from the client, no ownership check on reads.

F-021HIGH · CVSS 7.5patched in two days

Password reset tokens guessable: sequential, brute-forceable in under an hour

Tokens minted from a counter, not a CSPRNG.

F-008MEDIUM · CVSS 5.9fixed, rate limits in place

Login endpoint unthrottled, credential stuffing possible

No rate limit or lockout on the auth endpoint.

Full report list on request.

From finding to verified fix.

  • during the hunt

    Live notifications

    • Criticals within 4 hours, on the agreed channel
    • Every alert with a working PoC, not just a flag
    • The same channel for your questions, while the hunt runs
  • on delivery

    The signed report

    • Executive summary: scope, method, findings, business risk
    • Every finding with CVSS, PoC and the attack path
    • NIS2 / ISO 27001 evidence mapping, PAdES-B-T + timestamp
    • Prioritized remediation at the root, not the symptom
  • no extra cost

    Retest and fix verification

    • Remediation advice on every finding
    • Review of your fix before you ship
    • Retest as soon as the fix is live
    • The default on the standing hunt: every release

Multiple surfaces. One flat fee.

one flat fee
  • Multi-app, API and mobile scope, flat, in writing
  • NIS2 / ISO 27001 program: evidence mapping, roadmap, readout
  • Your external CISO: questionnaire-driven, NIS2 trickle-down included

What the hunt includes

  • Deep recon: every domain, subdomain, API, endpoint
  • Business logic: IDOR, authz, race conditions, payment & checkout flows
  • Proof-of-concept per finding, reproducible, in the report
  • Signed report with CVSS and NIS2 + ISO 27001 evidence mapping
  • Retest on every release, not an add-on
  • Code-assisted (optional): give us repo access, every release's diff read for data-flow issues. File:line + PoC, not scanner outputoptional
  • Report and walkthrough in English or German

How pricing works

from

€99/ month

Starter · one deep hunt/month. Continuous Growth from €499/month. Annual ~20% off.

Published tiers on /pricing: Starter €99/mo, Growth €499/mo, Pro €999/mo, Business €2,499/mo. Enterprise custom. Free check first.

What the market charges right now: 2026 ranges by type, hidden costs, the flat comparison.

What moves the price

additional app or API surface+ flat, in writing
mobile or cloud scopefixed, in writing
code-assisted scope (repo access)+€1,500 audit · +€5,000/yr
NIS2 / ISO 27001 evidence mappingincluded
onboarding, scoping, reportincluded

Flat and predictable. No per-scan billing, ever. Annual by default, monthly also available; both in writing before we start.

guarantee

No High, no pay.

No validated High or Critical in the agreed scope, you don't pay. CVSS-scored, human-validated, in the signed report.

Agreed scope, signed report, CVSS scale. In writing in the contract.

Questions before you start?

The test, the price, code access, your data — every question answered in writing, every answer with the next step.

All the answers

Start with the free check.

Send us your domain. A researcher confirms your request, the check takes about 20 minutes (read-only, nothing reaches your systems), and then you have the short written report: what an attacker can realistically do with it. Yours whether or not anything follows. If we keep hunting: one flat annual fee, in writing.