Services Authorised. Focused. Evidence-led.

Test the path.
Strengthen the defence.

Authorised penetration testing across applications, cloud, internal and AI systems. We document findings for engineering and security teams to investigate and act on.

From a focused application test to a connected, multi-layer assessment.

Material study / 02Layered defence
Find the weak connection.
Strengthen the system around it.

01 / Identity & access

One account.
How much reach?

A stolen session. A newly disclosed flaw. An exposed workload credential. The opening may differ, but the next question is the same: what can it reach? We test the permissions that should keep one foothold from becoming something larger.

Material study / Access

A trusted identity should not be a master key.

Application permissions

Web applications & APIs

A valid login should not become another customer's data. We test where your application trusts a user, object or request more than it should.

  • Authentication, sessions & OAuth
  • Object access & tenant isolation
  • Business logic, REST & GraphQL

The evidenceReproduction steps tied to affected endpoints, roles and business impact.

Cloud identity

Cloud infrastructure & IAM

A workload can be secure in isolation and overprivileged in context. We trace identity and policy relationships across AWS, Google Cloud and Azure.

  • IAM privilege & cross-account trust
  • Workload identity & Kubernetes RBAC
  • Secrets, storage & data access

The evidenceDemonstrated privilege paths and the policy or configuration changes that address them.

From red to blue

The path shows where to tighten access, limit privilege and identify activity your defenders should be able to see.

02 / Delegated authority

A model can answer.
An agent can act.

AI & LLM red-teaming

A hostile instruction can arrive in a document, a search result or a tool response. The security question is what happens when that content meets an agent with real permissions.

Material study / Layers of authority
Input

What does it trust?

Prompt injection through direct input, retrieved documents and other untrusted content.

Context

What can it expose?

Retrieval, memory and tenant boundaries that should keep private information separated.

Action

What can it change?

Tool and MCP permissions, service identities and the actions an agent is allowed to take.

The evidence

Reproducible test cases connecting the input, permissions, tool behaviour and observed impact. Your team can see which boundary failed and what needs to change.

03 / Containment

Assume a foothold.
Test what holds.

Access to one part of the environment should not mean access to all of it.

Internal & assumed-breach testing

We begin with an agreed level of access and test how far it can travel. Identity controls, network segmentation and credential handling are tested together, not as separate checklists.

  • Active Directory & Entra ID
  • Credential exposure & lateral movement
  • Segmentation & detection opportunities

Give the blue team the other half.

Alongside the demonstrated path, we identify relevant telemetry and detection improvements. The work should explain both how access was gained and where defenders can intervene.

Material study / Containment

A boundary matters when it limits what comes next.

04 / Verified repair

Change the control.
Challenge it again.

Remediation & retesting

A patch is a change, not yet a result. We revisit the demonstrated issue and agreed bypass cases. Then separate what is resolved, what remains open and what could not be tested.

For the team making the change
The original path, practical remediation guidance and clear retest conditions.
For the person accepting the risk
Business impact, tested results, assessment limits and the remaining uncertainty.

The report follows the agreed scope. Retesting is recorded when included in the engagement.

GenauraAssessment record
Illustrative report structure

From finding
to informed action.

  1. 01

    Scope & conditions

    Assets, permissions, test window and limitations.

  2. 02

    Path & evidence

    Prerequisites, reproduction steps and observed impact.

  3. 03

    Remediation & detection

    Recommended changes and useful defender signals.

  4. 04

    Retest & residual risk

    What was retested, the result and what remains.

Structure shown for illustration. No client data or assessment results.

05 / Agree the boundaries

Rigorous testing.
Deliberate limits.

We test with your permission, not at the expense of your operations. Scope and safety are part of the engagement, not small print.

  1. 01

    Written authority

    Named assets, agreed techniques and third-party exclusions before testing starts.

  2. 02

    Operational limits

    Test windows, stop conditions and an escalation contact agreed with your team.

  3. 03

    Evidence handling

    Agree how sensitive evidence is collected, shared, retained and removed.

When conditions change, we pause.

Unexpected access, a third-party boundary or a risk to availability triggers a stop and review with your designated contact.

How we work safely

Start with a conversation

What needs
to hold?

Tell us about the system, the decision you need to make and your timing. We will work with you to define a useful scope.

Share a high-level outline first. An NDA can be arranged before sensitive details.