Visiminds Technologies, home

Security services · VAPT

Vulnerability assessment and penetration testing

We test your systems as an attacker would, and help your developers fix what we find.

Testing in three rounds shown as three rings around a target, each round going deeper, and after each round an arrow to the developers, who fix what was found

How we test

Each VAPT (Vulnerability assessment and penetration testing. Finding the weak spots in apps, APIs, networks and cloud, and testing them the way an attacker would.) is made for the client. One test shows the weaknesses on one day, and new code brings new ones. So we test in rounds.

  1. Scope

    We agree with you what to test, and how deep.

  2. Explore

    Active and passive reconnaissance (Looking for targets: collecting what is known about a system before testing or attacking it.): what an attacker could learn about your systems.

  3. Test in rounds

    Each round goes deeper than the last.

  4. Fix together

    With your developers, after each round.

  5. Plan

    A plan to reduce the risk, carried out with you.

What we test

What our engagements have covered.

A dashed frame marks the agreed scope around six kinds of target, web apps, APIs, payment systems, networks, cloud servers and devices, and a tester outside the frame checks what is inside it

Inside the scope we agree

We agree with you what to test, and how deep. Then we test what is inside that scope.

  • Web applications
  • APIs (Application programming interface. The interface one program uses to talk to another.)
  • Payment systems
  • Infrastructure
  • Networks
  • Cloud servers
  • Data storage and retrieval
  • Hardware devices
  • Secure coding (Writing software in ways that avoid common security weaknesses.) practices

From our work

Four of our engagements. Each client is described by its sector only.

Case study 1 · finance

Custom VAPT and a risk plan for a finance company

A test made for the client, in rounds, with fixes after each round. It covered API security, payment security, infrastructure, data storage and retrieval, and secure coding. A risk mitigation plan followed, and was carried out.

Case study 3 · India

Ethical hacking for a large organisation

Ethical hacking (Attacking a system with the owner's permission, to find weaknesses before a real attacker does.) and penetration testing (An authorised test that attacks a system the way a real attacker would, to find what can be broken.) for a large organisation in India, including testing for certification. We used active and passive reconnaissance, and put security controls in place.

Case study 5 · real estate technology

Custom VAPT and a risk plan for a real estate technology company

We helped fine-tune its security architecture. We tested in rounds, and fixed the issues with its development team after each round. The tests covered APIs, and data storage and retrieval.

Case study 7 · consumer hardware

Ethical hacking of a gaming device

A gaming device that works with gaming laptops, for a company in the Netherlands. We tested the device, its APIs and its cloud server, and reported the possible ways to attack it.

Between tests

Between our tests, Ivy Lens checks your code on every build, and Ivy Insight checks your running systems as often as you like.

Two named cards: Ivy Lens checks code, packages and app builds on every build, Ivy Insight checks hosts, cloud accounts and web applications as often as you like, and both write findings the same way on one severity scale

Source code, open source packages, secrets and setup files. It runs on your own computer.

Websites, APIs, networks, cloud accounts and more. It can run in your network.

Tell us what you need

Tell us what you want tested, and we will agree the scope with you. Write to info@visiminds.com.