Home/About
Who we are

A testing firm, not a scanning service

Lupine Security is an offensive security firm. We test web applications, APIs, networks and mobile estates the way an attacker would approach them — manually, with intent, and with a working exploit as the standard of proof.

Why we exist

The market is full of scans sold as tests

A great deal of what is sold as penetration testing is a licensed scanner, a lightly edited export, and a covering letter. It produces a long document, a high finding count, and very little that changes an attacker's odds. It passes an audit checkbox. It does not tell you whether someone can get in.

We built this firm around the opposite premise. Automated tooling is where an engagement starts, never where it ends. A scanner cannot chain two medium-severity issues into account takeover, cannot reason about your authorisation model, and cannot tell the difference between a reflected parameter and a genuine path to your data. A tester can. That is the work we sell.

The standard we hold

If we report something as exploitable, we have exploited it, and the report contains the evidence. If we could not demonstrate impact, we say so and grade it accordingly. We would rather hand you a short report you can act on than a long one you have to triage.

Principles

How we work

These are operating rules rather than marketing lines. They shape what we quote, what we refuse, and how engagements actually run.

Manual testing, led by exploitation

Tooling handles coverage and enumeration. Humans handle logic flaws, authorisation gaps, chained attacks and everything that requires understanding what your application is for. The majority of engagement time is hands-on.

Fixed price, agreed before we start

You get a scoped, fixed-price quote. No day-rate creep, no surprise invoice because the estate turned out larger than the sales call suggested. If scope genuinely changes, we stop and re-agree in writing.

Retesting is included

A finding is not closed until it is fixed and verified. Retesting of the issues we reported is part of the engagement, not a follow-on purchase. You receive updated evidence suitable for handing to an assessor.

Reports written for two audiences

An executive summary your board can read without a translator, and technical detail an engineer can reproduce from. Same document, clearly separated. Every finding carries reproduction steps, evidence and a specific remediation.

You talk to the tester

Not an account manager relaying questions. The person who found the issue explains it, and is available during remediation to confirm whether a proposed fix actually addresses the root cause.

Evidence mapped to your framework

If the test exists to satisfy ISO 27001, PCI-DSS, SOC 2 or DORA, the reporting is structured so the evidence lands where your assessor expects it. See compliance mapping.

Boundaries

What we will not do

Worth stating plainly, because the answer is not universal in this industry.

  • We do not test systems without documented authorisation. Every engagement requires written confirmation of ownership, or permission from the owner. No exceptions, including for the free finding offer.
  • We do not run destructive techniques. No denial of service, no data destruction, no changes that degrade a production service, unless you have specifically commissioned resilience testing and agreed the window in writing.
  • We do not exfiltrate more than proves the point. Where a finding exposes data, we capture the minimum needed as evidence, record exactly what was accessed, and destroy it on report delivery.
  • We do not inflate severity to justify the invoice. A Low is reported as a Low. Finding counts are a poor measure of a test and we decline to compete on them.
  • We do not resell scanner output as manual testing. Where a finding came from automated tooling, the report says so.
  • We do not hold your report hostage. Deliverables are yours, in full, including the raw evidence. Share them with whoever you like.
Standards

What we test against

Recognised methodologies, so results are comparable between engagements and defensible to an assessor.

PTES NIST SP 800-115 OWASP ASVS OWASP WSTG OWASP API Top 10 OWASP MASVS MITRE ATT&CK CVSS v3.1 / v4.0

Our six-phase process — scoping, reconnaissance, identification, exploitation, reporting and retest — is documented in full on the methodology page.

Who does the testing

Our testers hold OSCP and other OffSec qualifications, CREST individual certifications, and GIAC certifications. These are held by the individuals doing the work.

Lupine Security Ltd is not currently a CREST member company. We state that plainly because some frameworks and customer questionnaires specifically require a member company rather than certified individuals, and you should know which you are buying before you buy it. If your requirement calls for CREST member accreditation, tell us at scoping and we will say honestly whether we can meet it.

Placeholder — company details

These need your real details before launch. Company registration number, registered office address and cyber insurance cover. Send them over and this section becomes real.

See how we work before you buy anything

We will test one scoped target and hand you a verified finding, free, with the same evidence and write-up quality as a paid engagement.