the standing hunt · continuous

Your app keeps shipping.
Your pentest tests yesterday's app.

A standing pentest on your external web and API surface: after every release, human-verified, signed report with NIS2 / ISO 27001-ready evidence, one flat annual fee.

every release

retested after you ship, no per-scan billing

100% PoC

every finding with a working PoC

NIS2 · ISO 27001

signed report + evidence mapping, included, not certified

Funded startups that ship monthly+ and need current, signed evidence for a funding round or an enterprise security review; the standing hunt is your external CISO on a flat fee. Stable businesses that changed little but got their customer's NIS2 questionnaire start with the one-off audit and add continuous coverage later. When the report is asked for, you hand over one that is days old, not months.

The same engine hunts live bounty programs.

This pipeline hunts live bug-bounty programs every day. Your hunt runs on the same pipeline. Full report list on request.

Vercel
Zooplus
Exness
Crypto.com
fintechSaaSe-commerceaerospacecrypto
redacted
F-014CRITICAL · CVSS 9.1fixed in one release · bounty paid

IDOR: sequential order IDs expose other customers' full order history

Order ID comes from the client, no ownership check on reads.

F-021HIGH · CVSS 7.5patched in two days

Password reset tokens guessable: sequential, brute-forceable in under an hour

Tokens minted from a counter, not a CSPRNG.

F-008MEDIUM · CVSS 5.9fixed, rate limits in place

Login endpoint unthrottled, credential stuffing possible

No rate limit or lockout on the auth endpoint.

Full report list on request.

How the hunt runs

01

Your surface, in writing

Hosts, app, API, auth roles: exact scope in a signed authorization and rules of engagement, in writing, before the first probe.

02

Map + attack, 24/7

Our AI agent fleet maps the whole surface and probes the logic the way an attacker would; a named researcher verifies every PoC himself.

03

Every release, retested

You ship, the hunt runs again on what changed. Retest is not an event or an add-on. It is the default.

04

Signed report, always current

CVSS plus NIS2 / ISO 27001 mapping and prioritized remediation. The report is a standing document, not a snapshot of yesterday.

What the hunt includes

  • Deep recon: every domain, subdomain, API, endpoint
  • Business logic: IDOR, authz, race conditions, payment & checkout flows
  • Proof-of-concept per finding, reproducible, in the report
  • Signed report with CVSS and NIS2 + ISO 27001 evidence mapping
  • Retest on every release, not an add-on
  • Code-assisted (optional): give us repo access, every release's diff read for data-flow issues. File:line + PoC, not scanner outputoptional
  • Report and walkthrough in English or German

How pricing works

from

€9,900/ year

one surface, every release, billed annually. Monthly also available.

Need a one-off report (NIS2, SOC 2, board)? The deep audit runs once: from €3,500, one retest included. Code-assisted adds +€1,500.

What moves the price

additional app or API surface+ flat, in writing
mobile or cloud scopefixed, in writing
code-assisted scope (repo access)+€1,500 audit · +€5,000/yr
NIS2 / ISO 27001 evidence mappingincluded
onboarding, scoping, reportincluded

Flat and predictable. No per-scan billing, ever. Annual by default, monthly also available; both in writing before we start.

Who actually does the test?+

You get a human-verified PoC on every finding and a signed report. The researcher is named in the contract and reachable during the test and at the readout. Right now that is Samir Abis.

How is this different from a bug bounty?+

Fixed scope, fixed price, report guaranteed. A bounty gives you no coverage and no timeline, and you only pay when someone finds something. You need that report for SOC 2 anyway.

Does this replace a scanner?+

It complements one. A scanner lists what might be there, and you verify every flag yourself. We prove what an attacker can actually do, with a working PoC, a named researcher, and a signed NIS2 / ISO report a scanner cannot produce. The scanner keeps its job.

What happens if you find a critical?+

We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive happens without written sign-off.

Can you also look at our source code?+

Yes. Give us repo access; the agent reads every release's diff for data-flow issues, missing auth checks, and framework-specific misconfigs. Findings come with file:line references and a working PoC. On the standing hunt this is the natural extension: you ship, the code is read, the logic is retested. Flat add-on, in writing.

Start with the free check.

Send us your domain. A researcher confirms your request, the check takes about 20 minutes (read-only, nothing reaches your systems), and then you have the short written report: what an attacker can realistically do with it. Yours whether or not anything follows. If we keep hunting: one flat annual fee, in writing.