Booking engagements for Q3

We break it before your auditor does.

Fortiq is an offensive-security firm built for the compliance era. Senior red teamers and continuous AI-driven testing find the flaws attackers would — then hand you a report your SOC 2 and ISO 27001 auditor accepts without a fight.

Tested against
SOC 2ISO 27001PCI-DSSHIPAAOWASPMITRE ATT&CK
Evidence for
  • SOC 2 Type I & II
  • ISO/IEC 27001
  • ISO 27017 / 27018
  • PCI-DSS 4.0
  • HIPAA
  • GDPR Art. 32
  • OWASP ASVS / MASVS
  • MITRE ATT&CK
Two engines, one engagement

Machines find the many.
People find the ones that matter.

Automated scanners miss business logic; humans can't watch your attack surface every night. Fortiq runs both — and reconciles them so nothing hides in the gap between them.

Human-led 01 / manual

Manual red team

Senior operators — OSCP / CRTO / OSWE-caliber — treat your systems like a real adversary: chaining low-severity flaws into full compromise, abusing business logic, and testing the things a scanner will never think to try.

  • Business-logic & authorization abuse
  • Multi-step exploit chaining to real impact
  • Manual verification — zero false positives
  • Social engineering & phishing simulation
AI-driven 02 / continuous

Continuous AI testing

Between engagements, our AI agents re-crawl your surface, replay attack patterns against new deploys, and triage the noise — so a vulnerability introduced on Tuesday doesn't wait for next year's audit to surface.

  • Always-on surface & regression testing
  • Every finding triaged, ranked, de-duplicated
  • New-deploy diffing & drift detection
  • Findings routed straight to Jira / Slack
Every AI finding a human could exploit is verified by an operator before it reaches your report. No unreviewed scanner output, ever.
The engagement

A methodology, not a
scan-and-invoice.

Six phases, mapped to PTES and the MITRE ATT&CK lifecycle. You see progress at every stage — not a black box that returns a PDF three weeks later.

01

Scoping & rules of engagement

Pre-engagement

We define targets, windows, and a signed rules-of-engagement document before a single packet is sent. Scope is precise, mutual, and auditable — your legal and infra teams sign off first.

NDA + RoEAsset inventoryThreat profile
02

Reconnaissance & mapping

Recon

We enumerate the real attack surface — subdomains, APIs, cloud assets, exposed services, and forgotten staging environments — the same way an external attacker would, before you know it exists.

OSINTSubdomain enumCloud asset discovery
03

Threat modeling

Analysis

Findings are prioritized by what actually threatens your business — the crown-jewel data, the paths to it, and the trust boundaries that, if crossed, turn a bug into a breach.

STRIDEAttack treesData-flow review
04

Exploitation

Active testing

We prove impact by exploiting — safely and reversibly. Every finding comes with a working proof-of-concept, so there's no arguing whether a "theoretical" issue is real.

Manual exploitationPoC developmentChained attacks
05

Reporting

Deliverable

You get one report with two voices: an executive summary your board and auditor read, and technical write-ups with CVSS, evidence, and step-by-step remediation your engineers can act on today.

CVSS v3.1Exec summaryRemediation plan
06

Remediation retest

Attestation

Once you've fixed the findings, we retest and issue a formal attestation letter — the closing evidence your auditor needs to mark the control satisfied. Retesting is included, not an upsell.

Fix verificationAttestation letterAuditor-ready
Attack surface

Wherever the risk lives,
we test it there.

One firm across your whole stack — so findings connect instead of scattering across six vendors' PDFs.

SUR-01

Web applications

SPAs, dashboards, portals — OWASP Top 10 and ASVS, authentication, session, and access-control depth.

SUR-02

APIs & microservices

REST, GraphQL, and gRPC — broken object-level authorization, mass assignment, and rate-limit abuse.

SUR-03

Cloud & infrastructure

AWS, GCP, Azure, and Kubernetes — IAM misconfiguration, privilege escalation, and exposed control planes.

SUR-04

External & internal network

Perimeter and lateral-movement testing — from an attacker on the internet to one already inside.

SUR-05

Mobile applications

iOS and Android against OWASP MASVS — insecure storage, cert pinning, and API-side authorization.

SUR-06

People & process

Phishing, pretexting, and physical-adjacent social engineering — because attackers target the human path too.

The deliverable

What lands in your inbox.

A findings ledger, not a raw scan dump — severity-rated, CVSS-scored, evidence-backed, and written to be read by both your auditor and your engineers.

FORTIQ-2024-ACME-04 Penetration Test Report
Retest passed
Critical

IDOR exposes full customer PII export

FTQ-001 · CWE-639 · Broken Access Control
9.1CVSS
High

JWT accepts alg:none, forging admin

FTQ-002 · CWE-347 · Auth Bypass
8.2CVSS
High

S3 bucket world-readable, backups exposed

FTQ-003 · CWE-732 · Misconfiguration
7.5CVSS
Medium

Stored XSS in support ticket subject

FTQ-004 · CWE-79 · Injection
6.4CVSS
Low

Missing security headers on API origin

FTQ-005 · CWE-693 · Hardening
3.1CVSS

Risk at a glance

Critical 1 High 2 Medium 1 Low 1

Every finding ships with

  • Reproducible proof-of-concept
  • CVSS v3.1 vector & business impact
  • Step-by-step remediation guidance
  • Mapping to SOC 2 / ISO 27001 controls
Built for the deadline you're actually facing

Standards we hold
ourselves to.

You're not buying a scan — you're buying the confidence to sign the attestation. These are the commitments we make on every engagement.

48h
From signed scope to testing kickoff — not weeks in a vendor queue.
100%
Of findings manually verified. No unreviewed scanner output in your report.
0 upsell
Remediation retest and attestation letter are included in every engagement.
24/7
Continuous AI testing between engagements, so you're never blind for a year.
Before you ask

The questions buyers
actually send us.

Yes — that's the point. Our reports are written to the evidence standard auditors expect: scope, methodology, severity-rated findings, remediation, and a formal retest attestation letter. We map each finding to the relevant Trust Service Criteria or Annex A control, and we're happy to talk directly with your auditor if they have questions.
A scanner fires signatures and hands you the raw output. Our AI agents reason about your specific application — chaining requests, replaying attacks against new deploys, and triaging results — and everything exploitable is verified by a human operator before it reaches you. You get the coverage of automation without the false-positive avalanche.
Always. Every engagement starts with a mutual NDA and a signed rules-of-engagement document defining exact targets, testing windows, and escalation contacts. We test only what you authorize, and we stop and call you the moment we find anything that suggests an active compromise.
Yes. Once your team has addressed the findings, we retest them and issue an attestation letter confirming what's fixed — at no extra cost. A test that doesn't verify the fix isn't finished, so we don't treat retesting as a separate invoice.
Most engagements kick off within 48 hours of a signed scope. A focused web-app or API test typically runs 1–2 weeks including reporting; larger, multi-surface engagements are scoped individually. If you're up against an audit date, tell us — we plan backwards from your deadline.
That's most of who we work with. We write findings so a generalist engineer can act on them, prioritize ruthlessly so you fix what matters first, and stay reachable while you remediate. You don't need an in-house red team to get an audit-ready result.
Request an engagement

Tell us what you
need to prove.

A short scoping conversation, no sales theatre. Tell us the surface and the deadline, and we'll come back with an approach, a timeline, and a fixed quote.

  • A human replies, fast.Your message reaches our team directly — expect a response the same business day.
  • Confidential by default.NDA first, always. Nothing you share leaves the engagement.
  • Deadline-aware.Up against an audit date? Say so — we plan the engagement backwards from it.
Prefer email? hello@fortiq.io Responsible disclosure: security@fortiq.io

By submitting you agree to be contacted about your request. We never share your details. Read our privacy note.