Skip to content

Recurring pentests for systems that keep changing.

I test your agreed external attack surface: web applications, APIs and internet-facing services. I assess every finding personally. You receive prioritized results, help with remediation and retesting of your fixes.

View sample report

Security research: vulnerabilities reported to

Infrastructure, operating systems and specialist software

Counts: findings reported through my own security research.

What a finding can expose.

Three examples from my published security research show the consequences of flaws in externally reachable systems.

Opera

A subdomain takeover led to control of the SIP/VoIP destination infrastructure. Telephony clients could consequently be directed to infrastructure outside the operator’s control.

Public case study

ClickHouse

Two RBAC bypasses allowed intended permission checks to be circumvented. The assigned role did not constrain access as intended.

Published research

Keycloak

CVE-2026-1190: A missing expiry check allowed delayed SAML responses to be accepted beyond the intended time window.

Official Keycloak issue

#2 VDP Researcher Germany on HackerOne, Q1/2026 · VDP = Vulnerability Disclosure Program

An output your team can work with.

What is affected? What could the flaw cause? Who owns the fix? The report connects evidence and priorities with practical remediation steps and retest status.

The public sample includes a PDF report, a separately downloadable findings update and an HTML reading view. All systems, data and results in it are fictional.

View sample report

Fictional sample

API access across tenant boundaries

Priority
High · another tenant’s data readable
Owner
API team
Next step
Enforce tenant checks for every object access
Retest
Fix ready, retest pending

A clear scope. A verifiable result.

Before starting, we record which systems may be tested, which access is available and which methods and testing windows fit your operations.

Within the agreed scope

  • Internet-facing web applications
  • APIs, including test accounts you provide
  • Externally reachable IT services

Outside these packages

  • Internal networks and comprehensive cloud IAM audits
  • Native mobile apps and social engineering
  • Full Red Team

Hardware and firmware research is a separately commissioned reverse engineering engagement.

From testing to retesting

  1. 01 · Agree scope

    Record systems, test access, methods and testing windows in writing.

  2. 02 · Test and assess

    I use my own testing setup and personally assess every finding for reproducibility, relevance and impact.

  3. 03 · Support remediation

    Agree priorities and owners, hand findings to your team and work through practical remediation steps.

  4. 04 · Retest fixes

    Retest remediated findings within the agreed scope and update their status. Included during the active contract term.

A testing cadence that follows your changes.

Monthly for stable applications, weekly for regular releases, daily when frequent changes or critical exposure justify it. We agree scope and cadence before starting.

Monthly

Regular price: from €1,999 Promotional price: from €1,399

per month, excl. VAT

Monthly testing and a comprehensive findings update.

For stable applications with few changes to the external attack surface.

Weekly

Regular price: from €5,999 Promotional price: from €4,199

per month, excl. VAT

Weekly testing and an updated findings report.

For product teams shipping regular releases, new APIs and ongoing changes to internet-facing systems.

Daily

Regular price: from €9,999 Promotional price: from €6,999

per month, excl. VAT

Daily testing and an updated findings report.

For high-output startups, enterprises and critical infrastructure with frequent changes or critical exposure. Otherwise, monthly or weekly is usually enough.

Included in every package

Personal assessment, a prioritized report and agreed ticket handover. Time with operations, remediation support and knowledge transfer to help your teams improve security workflows across the organization.

All packages include retesting of remediated findings within the agreed scope and during the active contract term.

All prices are starting prices. The final monthly fee depends on the number and extent of the agreed scopes and may be higher. Your quote confirms the binding price. Systems, methods, testing windows and communication channels are defined before work starts. The cadence describes the agreed testing and report updates.

Work directly with the engineer doing the testing.

I handle your engagement and take personal responsibility for the technical assessment. We work through root causes, mitigations and testing criteria with operations and development using concrete findings.

Findings in your workflow

We hand findings to Jira, Linear or GitHub using an agreed format or access you provide. We assign owners and keep remediation and retest status traceable.

Availability and critical findings

Available capacity and parallel engagements, arrangements for holidays or illness, and the notification channel and response time for critical findings are agreed in your quote before work starts.

My own testing setup

You receive the testing service, assessed findings and collaboration with me. Customers receive no access to the tools or models used.

Technical background in the case study

Questions about cost and scope

How much does recurring penetration testing cost?

Regular monthly fees start from €1,999 for monthly testing, from €5,999 for weekly testing and from €9,999 for daily testing, excluding VAT. All prices are starting prices. The final monthly fee depends on the number and extent of the agreed scopes and may be higher. Your quote confirms the binding price. Book by 30 September 2026. Save 30% for your contract term. For pentest packages booked on or before 30 September 2026 (Europe/Berlin). The saving applies for the entire agreed contract term. We agree the project start separately. Terms are confirmed in your quote.

What determines the testing scope?

The authorized websites, APIs and internet-facing services, their complexity, available test access and operational constraints determine scope. The proposal records the systems and coverage. Custom reverse engineering is quoted separately based on the device, complexity and required test hardware.

Why is a one-off pentest often no longer enough?

A pentest is a snapshot of the agreed testing scope. New releases, library updates, additional API endpoints and configuration changes keep changing your external attack surface. Later changes and newly disclosed vulnerabilities are not automatically covered by the existing report. Recurring tests shorten the time that changes remain untested. Findings are assessed and remediated, then fixes are retested. One-off tests remain useful for a baseline assessment or before a launch. For systems under active development, testing frequency should match the pace of change and the risk.

Is monthly testing enough?

For stable applications with limited changes, monthly testing is often a practical start. Weekly testing suits regular releases. We recommend daily testing for high code output, multiple teams or critical external exposure, rather than for every business by default.

How is this different from an automated vulnerability scanner?

We agree the scope together. I review every finding for reproducibility and relevance, then help your team prioritize, remediate and retest. You receive professionally assessed results and work directly with the specialist responsible for the engagement.

Is retesting included in the price?

All packages include retesting of remediated findings within the agreed scope and during the active contract term.

Can findings go into our ticketing system?

Yes. We agree a handoff to Jira, Linear or GitHub using a suitable format or access you provide. Each finding includes priority, evidence, remediation guidance and retest status. We agree ownership together.

How are critical findings and absences handled?

I handle your engagement and take personal responsibility for the technical assessment. Available capacity and parallel engagements, arrangements for holidays or illness, and the notification channel and response time for critical findings are agreed in your quote before work starts.

Investigate hardware & firmware

Reverse engineering for routers, appliances and other devices. Separately commissioned, with a dedicated test setup and pricing on request.

Which systems should we test?

Bring your web applications, APIs and reachable services. Together we agree the scope, testing cadence and the right price.

View sample report

Security inquiry

Request a non-binding quote for a pentest package or custom reverse engineering. We agree scope, start date and terms with you personally.

Pentest prices are per month, excluding VAT. All prices are starting prices. The final monthly fee depends on the number and extent of the agreed scopes and may be higher. Your quote confirms the binding price.

Book by 30 September 2026. Save 30% for your contract term. For pentest packages and custom reverse engineering booked on or before 30 September 2026 (Europe/Berlin). The saving applies for the entire agreed contract term. We agree the project start separately. Terms are confirmed in your quote.

Do not send passwords, credentials, confidential vulnerability details or firmware files. We will agree secure exchange and testing authorization personally.

Privacy notice

This inquiry is not a booking and does not secure promotional terms. After submitting, please confirm your email address.