~$ rebootworks
working with us

do you do security on apps you didn't build?

yes. the security work stands alone. point us at a site or app you already have and we'll find the ways in, show you each one, and hand you a report with the fixes ranked, most serious first. we can do the fixes too, or your own team can.

most of the security work we do is on things other people built: the site the last agency delivered, the app your in-house developer wrote before they left, the platform you bought and customised. that's the normal case. we don't need to have written it to break into it, only a signed scope and enough access to test what's on it.

how it runs

  1. a short scoping call: what's exposed, how many applications, roles, and integrations, and what must not be touched
  2. scope, testing window, and rules of engagement in writing, plus sign-off from your hosting provider where they require it
  3. the test itself, done by hand by a tester who holds OSCP and CPTS. business-logic abuse and chained findings are what a scanner misses, and where most real breaches come from
  4. the report: a one-page summary for people who don't work in security, and a detail section with each finding, the steps to reproduce it, the evidence, the severity, and a specific fix
  5. a free retest once you've fixed things

who does the fixing

your call. if you have developers, the report is written so they can act on it without us. if you don't, or they're busy, we fix it. we'll say which findings need this week and which can wait for the quarter, so nobody drops everything for a low-severity header.

if the codebase itself is in question, not just its exposure, we can review it first and tell you in writing what shape it's in. and if the test finds nothing, you still get the report saying so, with scope and methods documented, which is what a client or insurer asks for.

scope and pricing are on the IT & security page. for the authorisation question, see is a pentest legal to run on our own systems?

read it in context