XECbuild
Request Assessment
Services

Find the flaws, or build without them.

Two ways to work with us. Either we spend a few weeks trying to break what you have already shipped, or we build the next thing with you and make sure there is far less to find.

01

Website & Web Application Development

Design and development of websites and web applications, in whatever language or framework fits the work, with the security controls built in from the first commit.

02

Custom Digital Solutions

Internal tools, dashboards, integrations and the systems that do not come off a shelf, built to fit how the business actually runs.

03

Web Application Security Testing

Deep-dive AI-assisted and manual testing that uncovers business logic flaws, access control issues such as IDOR, and injection vulnerabilities standard scanners miss.

04

VAPT & Penetration Testing

Full vulnerability assessment and penetration testing across applications, APIs and exposed infrastructure, under agreed rules of engagement.

05

Vulnerability Assessment

Systematic identification and prioritisation based on real-world exploitability rather than raw scanner severity.

06

Security Reviews & Hardening

Architecture and configuration review with the fixes applied, covering authentication, authorization, headers, secrets and cloud roles.

engagement snapshot
Duration2 to 4 weeks
Testing styleAI + Manual
Reportingcontinuous
Lead time2 weeks
Penetration testing

Included areas

Scope is agreed up front. These are the surfaces we cover in a standard engagement.

01

Web Applications

Injection, access control, session handling, client side trust and file handling across the full authenticated surface.

02

APIs

REST and GraphQL. Object level authorization, mass assignment, resolver logic and undocumented routes.

03

Authentication

Registration, login, MFA, password reset, token lifetime and revocation, federated flows.

04

Authorization

Role boundaries, tenant isolation, privilege escalation paths and inherited permissions.

05

Business Logic

Pricing, quotas, workflow state, refunds and any process where the order of operations carries value.

06

Cloud Configurations

IAM policy, storage exposure, secret management, network boundaries and metadata access.

07

Source Review

Optional. Targeted review of the code behind high risk flows to confirm root cause and reduce guesswork.

Methodology

Five stages, run in order, documented as we go.

  1. 01

    Scope Definition & Rules of Engagement

    Understanding the exact footprint and legal boundaries before anything is touched.

  2. 02

    Reconnaissance & Vulnerability Identification

    Active and passive discovery of the target's attack surface using AI intelligence and custom tooling.

  3. 03

    Deep Manual & AI-Assisted Testing

    Combining automated AI analysis with deep hands-on testing of business logic, authorization, and APIs.

  4. 04

    Exploitation & Risk Validation

    Proving real-world impact through weaponized Proofs of Concept, verifying tenant isolation, and eliminating false positives.

  5. 05

    Reporting & Actionable Remediation

    Clear technical evidence, step-by-step reproduction guides, and stack-specific fixes delivered directly to your engineers.

Secure web development

Built by the people who break things.

Whatever stack you already run. The controls below are the starting point of the build, not a hardening pass bolted on at the end.

01

Any stack

Next.js, Django, Rails, Laravel, Go, Spring. We work in what your team already runs rather than migrating you onto ours.

02

Secure by default

Deny-by-default authorization, parameterised queries, output encoding and a strict Content Security Policy are the starting point, not a hardening pass afterwards.

03

Authentication done once

Session handling, MFA, password reset and token revocation built against the failure modes we spend the rest of our time exploiting.

04

Hardened delivery

Security headers, dependency policy, secret management, least-privilege cloud roles and reproducible builds wired into the pipeline.

05

Tested as it ships

The people who build it are the people who attack it. Each milestone is reviewed adversarially before it reaches production.

06

Handover you can run

Documented architecture, threat model and the reasoning behind each control, so your team can extend it without reopening the holes.

What you receive

Deliverables land in a shared workspace, with critical findings sent as soon as they are confirmed rather than held until the end of testing.

Executive Summary

Two pages for leadership. Risk posture, themes and what to prioritise.

Technical Report

Every finding with severity, affected assets and reproduction steps.

Proof of Concept

Working requests or scripts so your team can reproduce the issue.

Risk Ratings

CVSS v3.1 plus a business context rating we agree with you.

Screenshots

Annotated evidence captured at the point of exploitation.

Remediation Guidance

Specific fixes for your stack with code snippets and architectural guidance.