Skip to content
A VaultFifty1 studio: software engineering, DevOps & AI at vaultfifty1.com →
tr3labs

Assessments

What we test, how we test it, and what you receive

Five focused service types. Each engagement is scoped in writing before any work begins, and every deliverable is built to be acted on, not filed away.

01 Web & API Testing

Scope

  • Authentication, session management and account recovery flows
  • Authorisation: role, tenant and object-level access control
  • Input handling: injection, file handling, deserialisation
  • Business-logic abuse: workflow bypasses, race conditions, payment and quota logic
  • API-specific concerns: excessive data exposure, mass assignment, rate limiting

Method

Primarily manual testing with purpose-built tooling where it helps. We test with agreed accounts against agreed environments, and we never run destructive or availability-impacting checks without explicit sign-off.

Deliverable

A written report with an executive summary, reproducible findings (exact requests, affected routes, evidence), and remediation ordered by real risk. A retest of fixed findings is included when agreed in scope.

02 Cloud Security Review

Scope

  • Identity and access management: roles, policies, key and credential hygiene
  • Network exposure: public endpoints, security groups, ingress paths
  • Data stores: encryption, access policies, backup exposure
  • Secrets management and configuration drift
  • Logging, monitoring and alerting coverage

Method

Read-only review using scoped credentials you provision, combined with architecture walkthroughs with your team. We do not need, and do not ask for, production admin access.

Deliverable

A prioritised findings list where each item names the affected resource, the risk in context, and the specific configuration change that resolves it.

03 Application Security Review

Scope

  • Authentication and authorisation logic in code
  • Input validation and output encoding at trust boundaries
  • Secrets handling, cryptography use and dependency risk
  • Security-relevant architecture: trust boundaries, tenancy, data flow

Method

Code-assisted review focused on the paths an attacker would take, not a line-by-line audit of the whole codebase. Access via a read-only repository grant or supervised walkthrough, whichever you prefer.

Deliverable

Findings tied to specific files and code paths, each with concrete remediation guidance your engineers can implement directly.

04 Digital Forensics

Scope

  • Evidence acquisition and preservation with a documented chain of custody
  • Disk, memory and log analysis across affected systems
  • Timeline reconstruction: initial access, movement, actions taken
  • Root-cause analysis of the entry path and scope of exposure
  • Indicators of compromise for your monitoring going forward

Method

Forensically sound handling from the first touch: originals are imaged and hashed before analysis, every step is logged, and findings are tied to verifiable artefacts rather than speculation.

Deliverable

A certified forensic report suitable for legal, insurance and compliance proceedings, with a plain-language account of what happened and concrete steps to close the entry path.

05 Compliance & Certification Readiness

Scope

  • HIPAA: safeguards review and risk analysis for handlers of health data
  • PCI DSS: scoping, gap assessment and remediation toward attestation
  • SOC 2: control design and evidence preparation for Type I / Type II audits
  • ISO 27001: ISMS build-out, risk treatment and internal audit before certification
  • Ongoing evidence collection habits so the next audit is cheaper than the first

Method

Gap assessment against the target framework first, then hands-on help implementing the missing controls: policies, technical safeguards and monitoring. Certification itself is issued by accredited auditors; we prepare you and support you through their audit.

Deliverable

A control-by-control gap report, a prioritised remediation plan with owners, and audit-ready evidence, plus support alongside your auditor or QSA until the certificate or attestation is in hand.

Full capabilities

Everything we test, review, and defend

Beyond our core assessments, the studio delivers a full range of offensive, defensive, and compliance engagements. Tell us what you need — these are the capabilities we bring.

01

Application Security

  • Web Application Penetration Testing
  • API Penetration Testing
  • Mobile App Penetration Testing
  • Secure Source Code Review
  • SaaS Security
  • E-commerce Security
  • DevSecOps

02

Network & Infrastructure

  • Network Penetration Testing
  • Wireless Penetration Testing
  • Firewall Security Audit
  • Server Hardening

03

Cloud Security

  • Cloud Security Audit
  • Cloud Configuration Review
  • AWS, Azure & GCP Hardening
  • Container & Kubernetes Security

04

Threat Simulation

  • Red Team Engagements
  • Social Engineering
  • Phishing Simulation

05

Industrial & IoT

  • IoT Penetration Testing
  • OT Security Assessment
  • ICS / SCADA Security Testing

06

Governance, Risk & Compliance

  • ISO 27001 Readiness
  • SOC 2 Readiness
  • PCI DSS
  • HIPAA
  • SAMA & SWIFT CSP
  • Security Architecture Review

07

Data Privacy

  • DPO as a Service
  • GDPR Compliance
  • PDPL Assessment
  • Data Privacy Consulting

08

Managed Security

  • Managed Vulnerability Scanning
  • Managed Threat Hunting
  • Security Operations (SOC)
  • Virtual CISO (vCISO)
  • Annual Security Program

09

Incident Response & Forensics

  • Digital Forensics
  • Incident Response
  • Compromise Assessment

Engagements are fixed-scope and fixed-price once agreed. If you are not sure which assessment fits, describe your situation and we will recommend a scope, including telling you honestly if you do not need us yet.