What we test, what we find, and what changed.
Ten representative engagements across five sectors. Security work cannot be shown off the way a website can, so each one is told as the report would tell it: the scope, the framework, what we found and what was true at retest.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
01
A multi-tenant invoicing platform
Web app & API pentest
One tenant could read every other tenant’s invoices · OWASP ASVS 5.0 · L2
02
A regional credit union
NIST CSF 2.0 audit
A maturity baseline the board could actually read · NIST CSF 2.0 · Profile
03
A virtual-care platform
API security test
The mobile API that trusted the app too much · OWASP API Top 10 · 2023
04
A direct-to-consumer retailer
PCI DSS v4.0.1 readiness
Every script on the payment page, accounted for · PCI DSS v4.0.1 · 6.4.3 / 11.6.1
05
A B2B HR software company
SOC 2 readiness
Ready for the auditor before the auditor arrived · SOC 2 · Security + Confidentiality
06
A mid-sized law firm
Web app pentest & ISO 27001 gap
A document portal that leaked through its filenames · ISO/IEC 27001:2022 · Annex A
07
A consumer lending fintech
Pentest & secure code review
Business logic that let a loan approve itself · OWASP WSTG · Business logic
08
A multi-location dental group
Web app pentest
A booking plugin that exposed the appointment book · OWASP Top 10:2025
09
An online marketplace
Web app & API pentest
Coupons that stacked forever · OWASP API Top 10 · API6
10
An accounting practice
CIS Controls v8.1 audit
Essential hygiene, prioritised into one quarter’s work · CIS Controls v8.1 · IG1
Have something that needs testing?
Tell us what you ship, who is asking for proof, and when you need it. We will come back with a scope and a range.
Let’s Connect
or email hello@penspycyber.com