Offensive security & penetration testing

We hunt the gaps before adversaries do.

Lupine is an offensive security firm testing web, APIs, networks, and mobile systems like real attackers.

What we are building

The testing firm we wanted to hire.

Named testers, reachable

You know who is testing your systems, and you can talk to them directly — during the engagement and while you fix what they found.

Fixed price, agreed upfront

Scoped properly before we quote, so the number you approve is the number you pay. No day-rate creep, no invoice that grew in the telling.

Retesting as standard

A finding is not closed until it is fixed and verified. Retesting is part of the engagement, not the follow-on purchase it is elsewhere.

Reports you can act on Monday

Reproduction steps an engineer can follow, a summary your board can read, and remediation that names the change to make — not “implement input validation”.

One real finding. Free. No sales call first.

We will test a scoped target in your development, UAT or production environment and hand you one verified Medium, High or Critical vulnerability — written up properly, at no cost.

Start the authorisation
Standards & frameworks

Testing that satisfies the people auditing you

Our reports map directly to
your compliance requirements
ISO

ISO 27001

Evidence for A.8.8 technical vulnerability management and A.8.29 security testing in development.

PCI

PCI-DSS 4.0

Requirement 11.4 penetration testing, including segmentation validation for in-scope environments.

GDPR

UK GDPR / EU GDPR

Article 32 security testing

Evidence of a process for regularly testing, assessing and evaluating the effectiveness of technical security measures.

DORA

DORA

Digital operational resilience testing

Annual testing for all in-scope EU financial entities; threat-led penetration testing every three years for those designated significant.

SOC

SOC 2

Monitoring of controls, CC7.1

Evidence that vulnerabilities are identified through a defined process and remediated. Testing cadence and closure evidence both matter to the auditor.

SAMA

SAMA Cyber Security Framework

Penetration testing

Required for Saudi financial institutions, covering internal and external surfaces with defined remediation timelines.

NCA

Saudi NCA ECC

Penetration testing controls

Periodic testing of internet-facing services and internal systems, with results reported to the appropriate governance body.

UAE

UAE Information Assurance Standard

Technical compliance and vulnerability assessment

Regular assessment for entities in scope of the UAE IA Standard, including critical infrastructure operators.

How an engagement actually runs

Methodology
  1. Scoping & authorisation:

    We agree targets, environments, timing, rules of engagement and explicit exclusions. Both parties sign before anything is touched.

  2. Reconnaissance:

    Passive and active mapping — DNS, certificate transparency, exposed infrastructure, technology fingerprinting and attack surface enumeration.

  3. Vulnerability identification:

    Systematic testing against OWASP, PTES, NIST SP 800-115 and CWE, combining tooling for coverage with manual work for depth.

  4. Exploitation & escalation:

    Confirmed issues are exploited within scope, chained where possible, and escalated to establish genuine business impact rather than theoretical risk.

  5. Reporting:

    Technical findings with reproduction steps, evidence and CVSS, alongside an executive summary framing risk in business terms.

  6. Remediation & retest:

    A working session with your engineers, then a retest of remediated findings and a reissued report confirming closure.

Global coverage

Ready to test wherever you are, worldwide.

Our remote testing removes location barriers. We align with regional standards, including UK/EU GDPR, SAMA CSF, NCA ECC and NESA.

United States Canada United Kingdom Germany Egypt United Arab Emirates Saudi Arabia South Africa India Philippines Singapore Malaysia Australia New Zealand

Find out what an attacker would find first.

Start with a free verified finding, or book a scoping call and get a fixed-price quote within two working days.