Skip to content
Mockingjay

Expert-led pentests, delivered like software.

Scope an engagement in the platform, choose black, grey or white-box testing, and watch findings arrive as testers log them. Talk to the people breaking in, request retests with one click, and export reports your auditors accept.

ENG-2026-014 · Grey box · Oct 6 – Oct 17Q4 external, API & LLM assistant pentest
AMDVJTTesting live · Day 6Request retest
OverviewTest planFindings · 9Messages · 3Scope & credentialsReports
Test plan coverage88 / 142 cases
  • Authentication100%
  • Session management100%
  • Authorization & access control82%
  • Input validation & injection64%
  • Business logic45%
  • API security72%
  • LLM prompt & tool abuse38%
  • Reporting & retest0%
Findings as they land2 C · 3 H · 4 M
  • 12m agoCriticalPrivilege escalation via role parameter tamperingadmin.example.com · AM · repro attached
  • 3h agoHighIndirect prompt injection via uploaded PDFsupport-assistant · JT · 4 payloads
  • YesterdayCriticalBOLA exposes any tenant’s invoicesapi.example.com · DV · confirmed
  • YesterdayHighPassword reset token not bound to sessionapp.example.com · AM
  • Oct 8MediumVerbose stack traces on 500 responsesapi.example.com · DV
  • Oct 7MediumMissing rate limit on OTP verificationapp.example.com · AM
Tester channel
  • AM
    Tester · AM 11:42Changing role=admin in the profile update body grants full admin. Repro and PoC are on MJ-1039.
  • SL
    You 11:50Thanks. Is this staging only, or does prod share the handler?
  • AM
    Tester · AM 11:53Same handler per the source you shared. Recommend a hotfix before release; we’ll retest as soon as it’s deployed.
Message the testers…
Scope: app.example.com · api.example.com (148 endpoints) · support-assistantRules: no DoS · staging data only · 09:00–21:00 SGTMethodology: OWASP WSTG · OWASP API Top 10 · OWASP LLM Top 10
Illustrative product view · sample data

Decide how much the testers know going in.

The same team, the same platform, three levels of access. Pick per target, or combine them in one engagement.

One team for every target.

Book a single engagement or combine targets into one, with a single test plan and a single report.

  • Web applicationsSPAs, multi-tenant SaaS, admin portals
  • Mobile appsiOS and Android, with backend APIs
  • APIsREST, GraphQL, gRPC and webhooks
  • External networkPerimeter, VPN and exposed services
  • Internal networkActive Directory and lateral movement
  • Cloud configurationAWS, Azure and Google Cloud reviews
  • GenAI applicationsChatbots, RAG and AI agents
  • Thick clientsDesktop apps and their services

Everything a pentest should have been all along.

MethodologyOWASP WSTG · OWASP MASTG · OWASP API Security Top 10 · OWASP LLM Top 10 · PTES · NIST SP 800-115

PTaaS questions

How long does an engagement take?
It depends on scope. A typical web application or API engagement runs 5–10 business days of active testing. We confirm the timeline during scoping.
Which approach should we choose?
Grey box is the right default for most SaaS applications. Choose black box to measure external exposure, and white box for systems where a missed flaw would be costly.
Are retests included?
Yes. Every engagement includes two free retests, so you can confirm fixes without a new statement of work.
Who does the testing?
Experienced offensive security engineers. Every tester is vetted to industry standards before working on a customer engagement.

Scope your next pentest in one call.

Tell us what changed and what your auditors need. We'll come back with a test plan, approach and timeline.

Book a demo