Mini Pentest
One complete day of manual testing for a clearly scoped application or API. Prioritized findings by the following business day.
- 8 hours of manual testing
- €1,399 fixed price
- Ideal before releases and as a first pentest
With the help of penetration tests, we can uncover security vulnerabilities and issues in your IT infrastructure, apps, and websites.
Penetration tests are the cornerstone of IT security and should be conducted continuously - for example, when there are changes in the code. Regular penetration tests of relevant assets, such as web applications, APIs, mobile apps, or general services, foster trust in your IT security.
Kick-off with your team, scope alignment & access clarification.
In-depth manual testing, continuous updates via your preferred channel.
Retest of fixes, management workshop & delivery of final report.
Dedicated team of senior pentesters with experience in FinTech, HealthTech, Industry & SaaS.
A penetration test is a targeted, manual security test against systems, applications, or entire infrastructures. Our Offensive Security experts think and act like attackers to uncover vulnerabilities before they can be exploited. Typical targets include web and mobile applications, APIs, internal and external networks, or IoT and cloud environments.
Every test is individually tailored to your company: We jointly define scope, testing depth, critical assets, and ground rules. This ensures that your systems remain available and the test delivers meaningful results. Larger companies often bring existing asset lists or ISMS structures - we integrate this information directly into the planning.
At the end, there's always a result that enables decisions: An understandable management summary, a technical section with proof-of-concepts, CVSS classification, reproduction steps, and clearly prioritized action recommendations. Upon request, we accompany your team during fixing and conduct retests until all findings are properly closed.
Avoid security incidents before they happen - we provide you with clarity about your risk within days.
We combine in-depth, manual testing with collaboration on equal footing. The focus: actionable findings, rapid implementation, and long-term security.
All pentests are conducted by senior consultants with bug bounty experience. Complex scopes, regulated industries, and custom software are part of our daily business.
Management summary, risk assessment, technical details, PoCs, and prioritization - structured in one document. So technical and leadership teams can make immediate decisions.
Kick-off within five business days. Parallel testing teams or express slots are available for time-critical projects - without compromising quality.
We evaluate findings in the context of your business model and show what impact an exploit would have - including an action plan for your team.
Daily stand-ups, Slack channel, or quiet background work - you decide how closely we work together and how often you receive updates.
Retests and knowledge transfer are included. Upon request, we support directly with implementation of measures or coach your team.
We've had the privilege of working with some of the world's leading companies and strengthening their IT security.
Many of our clients prefer not to be publicly named for understandable reasons. So you can still get a sense of our capabilities, we refer to our activities in the bug bounty space: Our pentesters regularly report critical vulnerabilities to corporations like PayPal, Tesla, and Apple and are listed in their Hall of Fame. We're happy to provide anonymized reference reports or personal contacts upon request.
Experiences from real projects
„I've been really impressed with DSecured. The results they delivered exceeded our expectations. They found a wide range of IT problems and severe vulnerabilities and always communicated clearly. Working with them has been straightforward and reassuring.“
„The security of our customers’ data is our top priority. Thanks to DSecured, we were able to improve the resilience of our systems and realize how important the topic of "Shadow IT" is. The commitment of the team and their skills made the crucial difference for us.“
„DSecured was able to discover a surprising number of previously undetected security gaps in our infrastructure. The Argos platform as well as classic penetration testing were used for this. We really appreciated the honest advice on the subject of IT security and automation and would like to thank Mr. Strobel for this.“
„Mr. Strobel and his team regularly carry out penetration tests against our automation platform - and always find what they are looking for. The results are presented clearly and reproducibly. Communication has so far taken place via short channels, for example via Slack. We can definitely recommend DSecured.“
Your audits and certifications are our focus. We follow the requirements of national and international standards and document the test so you can use it directly for compliance evidence.
We follow BSI guidelines for penetration testing and integrate the requirements of your government or KRITIS projects.
Open documentInternationally recognized standard for web and API security. Our findings reference OWASP categories and CVSS scores.
Open documentThe cost of a penetration test varies depending on complexity, scope, and duration. Here are two typical examples from our practice.
Standard web application with backend API, user authentication, and database integration. Greybox test with documentation.
Complex SaaS solution with multiple user roles, multi-tenant architecture, extensive API, and SSO/MFA integration.
Learn more about the various cost factors, potential savings, and additional pricing examples for different types of penetration tests.
Not sure if a comprehensive pentest is necessary? Our Mini Pentest offers a quick, focused security check for critical areas of your application. Perfect as a first step or for quick pre-release security validation.
Focused examination of the most critical vulnerabilities
Transparent fixed price - no hidden costs
Fast, actionable reporting as ticket list
Popular add-ons:
A large part of the internet is based on websites and web applications.
Modern websites and SPAs usually communicate with some kind of API.
Fully automated vulnerability scanning for your IT infrastructure or application.
Adaptive AI testing of one web application or API at a fixed price of €899.
Modern IT landscapes change quickly. That's exactly why regular pentests are mandatory: We uncover vulnerabilities before attackers exploit them and provide you with a clear basis for decisions. From web and mobile applications to APIs and cloud platforms, we test every relevant asset in a targeted manner.
Compliance requirements like ISO 27001, GDPR, TISAX, SOC 2, or industry-specific regulations regularly require verifiable security measures. A documented penetration test provides evidence to auditors, customers, and partners - and prevents costly security incidents.
We find known and unknown vulnerabilities, misconfigurations, and logic errors - including reliable proof-of-concepts.
Each finding includes prioritization, technical details, and action recommendations. So your team can start fixing immediately.
Retests ensure that all measures are effective. Upon request, we document the results for your auditors.
We show you how to improve your security processes, which investments are worthwhile, and where automation can help.
Complete test with SQL Injection, Broken Access Control, and XSS vulnerabilities.
Black-box test with critical LFI, SSRF, and missing authorization checks.
The duration of a penetration test depends heavily on the complexity of the system to be tested and the scope of the desired tests. A comprehensive penetration test usually takes between 3 days and 3 weeks. You can obtain recommendations on the duration from our experts.
Pure IT security audits can hardly be compared with a pentest. Although they uncover vulnerabilities, they cannot test the actual exploitability. A penetration test is therefore the better choice if you want to test the security of your systems realistically.
Our team excels in numerous sectors, including but not limited to finance, healthcare, and technology. Each field requires a tailored approach, & that's where our bespoke expertise shines brightly.
The end product should usually be a report. This contains a management summary and a technical section. The latter is intended for the IT department and contains detailed information on the vulnerabilities found as well as recommendations for remediation.
We treat data protection seriously & adhere to strict confidentiality protocols. During tests, all information is handled with the utmost discretion. Plus, we're engaged under clear legal frameworks that safeguard all parties involved.
This is not a problem - there are several ways in which our team can test a non-public system. For example, VPN or on-site.
Most companies repeat their penetration tests once a year. However, modern IT is dynamic - so security tests should also be carried out more frequently - or at least when there have been major changes. Pentest as a Service closes the gap to the classic pentest.
If a critical flaw is uncovered, we promptly inform you while simultaneously recommending immediate actions to mitigate the risk. Our goal is to aid you in fortifying your systems swiftly & effectively.
It depends on the penetration test - for a penetration test against API or web applications, Burp Suite is the tool of choice. DSecured has also developed a number of private tools for finding vulnerabilities that are always used. Other tools worth mentioning are of course nmap, Nessus, Metasploit and many more.
Yes, we can perform a penetration test with different levels of intensity - starting from a rough one, covering only the most important things, to a regular, very detailed penetration test.
The simplest method is to use a special isolated test system. This is created exclusively for the test and does not contain any real data. This ensures that no damage is caused to your production system.
Have questions about our services? We'd be happy to advise you and create a customized offer.
We'll get back to you within 24 hours
Your data will be treated confidentially
Direct contact with our experts
Laravel is one of the most popular PHP frameworks. We test your Laravel application for security vulnerabilities.
WordPress is the world's most popular CMS. We test your WordPress installation for security vulnerabilities.
Typo3 is a popular CMS in the enterprise sector. We test your Typo3 installation for security vulnerabilities.
Django is a popular Python framework. We test your application and improve its security.
Drupal is a modular CMS. We search for vulnerabilities in your application.
Spring Boot is a popular Java framework used in the enterprise sector.
ASP.NET is a popular framework for web application development from Microsoft.
Penetration testing with a focus on NodeJS applications
The PHP framework Symfony is used in many projects. We test your application.
Many companies use Software as a Service (SaaS) solutions.
Cost-effective and efficient vulnerability assessment for your business.
GenAI, especially LLM systems, have special requirements for penetration testing and IT security.
Internal and external networks are the backbone of modern IT infrastructure.
Penetration testing with a focus on the internal network.
Penetration testing with a focus on the external network.
Continuously and quickly check if there's a problem - PTaaS