For companies and development teams
Application and infrastructure penetration testing
Find out how an attacker could reach your data. We test the agreed applications or infrastructure, explain the vulnerabilities we find and recommend fixes. TunaSec is a nonprofit team based in Brno and Prague with experience testing company systems.
Discuss a penetration testWhat we can test
A test can be useful before an application goes live, after major changes or as a regular review. We choose the scope around your system and its risks.
Web applications
Authentication, user permissions, sensitive data handling and business logic. We also examine situations that routine functional testing does not cover.
APIs and cloud platforms
Access to data and functions through APIs, separation between users and the behaviour of client interfaces. We agree which parts of the platform to include.
Company infrastructure
Internal networks and available services from the perspective of an attacker who has already gained access. We look for ways to move further and reach important systems.
What you receive
- A report of the vulnerabilities found and an explanation of their impact.
- Descriptions of findings that developers and administrators can work with.
- Recommendations for fixes to help decide what to address first.
How the engagement works
Agree the goal and scope
We discuss the system, important data and your expectations. We define what to test, the access needed, timing and rules of engagement.
Carry out the test
We look for and verify vulnerabilities within the agreed scope. Testing takes place with the owner’s permission and under the agreed conditions.
Deliver and explain findings
You receive a vulnerability report and recommendations for fixes. We discuss what the findings mean for your system with your team.
Agree the next steps
We discuss how to act on the results. If you need fixes checked, we agree the scope of a follow-up review.
Experience from real projects
Liferay
Penetration tests of Liferay DXP, with vulnerability reports and recommendations for fixes.
Apify
Testing a cloud platform for web scraping and automation, including APIs and client interfaces.
Deepnote
Penetration tests of a platform for collaborative work with data science notebooks.
Common questions
How does a penetration test differ from an audit?
A penetration test aims to verify how an attacker could exploit weaknesses in a system. An audit can also review configuration and working practices. In our initial discussion, we choose an approach based on what you need to learn.
How much does a test cost and how long does it take?
This depends on the application or infrastructure, the access available and the test’s goal. Tell us what you want to test and your timing. We agree the scope, price and dates before starting.
What do you need before starting?
A description of the system, a list of the parts to test and the owner’s permission. We also agree the environment, any test accounts, a contact person and rules of engagement.
Does a test mean the system is secure?
A test describes findings within a particular scope and time. It cannot guarantee there are no other vulnerabilities. Its value is concrete information for fixes and ongoing security improvements.
What do you need to test?
Tell us about the application or infrastructure, your concerns and the timing you have in mind. Together we will choose an appropriate testing scope.
Discuss a penetration testDo your employees also need training?
Cybersecurity training for employees