fSecurity AI+

Pentest as a Service

Every attack surface. One program.

Every engagement combines AI-driven testing with senior human validation, under signed Rules of Engagement. Choose the surfaces, choose the cadence. Every finding arrives with proof and the exact fix.

By need

What you are trying to solve.

Continuous pentest program

Replace the annual pentest with a program that runs every month across your surfaces.

  • New cycle every month
  • Regressions caught after each release
  • Re-test with one click

Compliance evidence

Audit-ready evidence for PCI DSS, ISO 27001, SOC 2 and your financial regulator, from one testing program.

  • Findings mapped to controls
  • Internal, external and segmentation tests on schedule
  • Board-ready report

Identity and Active Directory

Attackers log in more than they hack in. Prove what a phished or weak credential reaches.

  • Password and credential audit
  • Kerberos, ACL and delegation abuse
  • Path to Domain Admin, proven

Rapid response to new CVEs

When a critical CVE or KEV drops, know within hours whether it is exploitable in your environment.

  • New CVEs and KEV checked against your assets
  • Safe exploit attempt, not a version check
  • Clear or exposed, with proof

AI systems and LLMs

Chatbots and integrated models are a new surface. We test them with the same discipline.

  • Prompt injection and jailbreaks
  • Data and system-prompt leakage
  • RAG poisoning and filter evasion

Release validation

Every mobile or web release gets attacked before your customers use it.

  • APK / IPA and API traffic per version
  • Regression on previously fixed findings
  • Evidence attached to the release

Pentest types

What we test, by type.

Duration is set by scope at kickoff; most engagements deliver within days, not weeks.

Web applications

Portals, online banking, e-commerce and internal apps.

What we test

  • OWASP Top 10 and access control
  • Business logic and session handling
  • Proof of exploitation per finding

APIs

REST, GraphQL and partner integrations.

What we test

  • BOLA / IDOR and broken authorization
  • Injection and data exposure
  • Rate limiting and business logic

Mobile applications

Android, iOS and HarmonyOS, with their backend APIs.

What we test

  • Binary analysis, secrets and permissions
  • Authentication, tokens and sessions
  • Local storage and API traffic

Aerospace infrastructure

Ground segments, data links and mission systems.

What we test

  • Ground stations and mission control networks
  • Telemetry, data links and interfaces
  • Embedded systems and supplier integrations

External network

Everything reachable from the internet.

What we test

  • Domains, public IPs, DNS and subdomains
  • Web, mail and VPN servers
  • Validated exploitation of exposed CVEs

Internal network

What happens once someone is already inside.

What we test

  • Assumed breach from a workstation
  • Lateral movement and segmentation
  • Path to critical assets, proven

Identity and Active Directory

Directory, credentials and privilege escalation.

What we test

  • Kerberos, ACL and delegation abuse
  • Password and credential audit
  • Path to Domain Admin, proven

Cloud and Kubernetes

AWS, Azure, GCP and container platforms.

What we test

  • IAM, roles and privilege escalation paths
  • Exposed storage and secrets
  • Cluster RBAC and escape paths

Wireless

Corporate and guest networks at every site.

What we test

  • Rogue access points and evil twin
  • Key strength and enterprise auth
  • Segmentation from guest to corporate

IoT and OT

Devices, industrial control and field equipment.

What we test

  • Firmware and default credentials
  • Industrial protocols and network exposure
  • Safe testing windows agreed with operations

Social engineering

Phishing, vishing and pretexting with real impact.

What we test

  • Phishing and pretexting campaigns
  • Vishing
  • Credentials replayed to prove impact

AI systems and LLMs

Chatbots, assistants and models wired into your systems.

What we test

  • Prompt injection and jailbreaks
  • Data and system-prompt leakage
  • RAG poisoning and filter evasion

Also in the catalog

Quoted by scope, delivered with the same method. If your surface is not listed, ask.

Segmentation testingRed team operationsPassword and credential auditsAssumed-breach exercisesPhishing impact testing

Need broader coverage?

Combine three or more types into a program. Typical: external + internal + API, or web + API + mobile. Coverage is scoped on the call.

Included in every pentest

  • Rules of Engagement and NDA
  • AI-driven testing with senior validation
  • Executive and technical report
  • Proof of exploitation
  • Re-test after the fix
  • Live walkthrough

One-time vs. continuous

A one-time pentest is a photograph. A continuous plan keeps the testing running: new cycles every month, regressions caught after each release, re-test included and a report that never goes stale for auditors and customers.

What you receive

  • Executive summary for leadership
  • Technical detail with severity, evidence and fix guidance
  • Proof of exploitation for each confirmed finding
  • Re-test after the fix
  • Live walkthrough and Q&A
  • Remediation support hours (continuous plans)