Penetration testing, security audits, and consulting for organizations that take IT security seriously. Because nothing matters more to people and organizations than the security of their data.
From a single web service to your entire infrastructure — every review ends with a clear, understandable report, no jargon.
Targeted, manual attack simulation on web applications, APIs, and networks — with an attacker's mindset, working on behalf of your security.
Systematic review of servers, networks, and configurations for known and overlooked vulnerabilities.
Assessment of your existing security measures, processes, and policies against common best practices.
Individual guidance on hardening measures, risk prioritization, and long-term security strategy.
Structured, transparent, with clear communication at every stage.
Together we define what gets tested, which systems are in focus, and what rules apply.
Mapping the attack surface — open services, technologies, possible entry points.
Controlled exploitation of identified vulnerabilities to demonstrate real-world impact.
A clear report with risk ratings, evidence, and concrete remediation guidance.
After remediation, I verify whether the vulnerabilities have actually been closed.
Every unchecked vulnerability is an open door. A test reveals what only an attacker would have seen before — and closes it.
All findings are discussed exclusively with you. An NDA is available on request.
Vulnerabilities are never published or shared — only reported and documented.
Reports that even non-technical decision-makers can understand and act on.
See report structure →Alongside security work, I also take on classic web development — from the website to the system behind it. Especially useful in combination: built securely from the start.
A controlled, simulated attack on your systems aimed at finding vulnerabilities before real attackers do. Unlike an automated scan, this is done manually and with intent.
Yes — as long as the test is based on a written agreement (scope & authorization). That's exactly what gets defined together during the scoping phase, before anything is tested.
The approach is controlled and coordinated with you. Critical tests (e.g. on production systems) are discussed in advance and can be shifted to test environments.
The price depends on scope and target systems — hence "pricing on request". After an initial conversation, you'll receive a tailored quote. What determines the price →
No problem — many clients start exactly there. An initial vulnerability assessment or consulting session lays the groundwork for everything else.
Tell me briefly about your project — I'll get back to you with a tailored quote.