Services
Manual penetration testing for web applications, APIs, mobile apps, thick clients, generative AI-powered applications, and networks of all types, all done by Senior level testers and above.
Our Bread and Butter is Penetration Testing
Every engagement is run by a Senior+ tester. Below are some of the types of penetration testing services you can expect (engagement duration is dependent on scope size and client needs).
Every Engagement Includes
- A named Senior+ tester on every call and on your engagement
- Critical findings reported the day they are found
- Communication every step of the way, at your preferred cadence
- Reproduction steps written for the engineer to reproduce the issue consistently and with minimal overhead
- A remediation walkthrough call
Typical window – 1–2 weeks
Web Applications
Looking to have your web application tested? You've come to the right place. Web Application Pentesting is our bread and butter here at 7Seas.
7Seas' web application pentest methodology is a heavily-manual approach that leverages the OWASP Testing Guide as the foundational methodology. We've tackled web applications across the spectrum of programming languages, from the modern to the tried and true. We focus on covering not only issues encompassing the OWASP Top 10 and application security best practices, but also more intricate vulnerabilities such as business logic flaws and authentication/authorization issues and bypasses.
Typical window – 1–2 weeks
APIs
Rolling out a new API and want to ensure it not only works as intended, but doesn't leave your company exposed? 7Seas can help you identify any vulnerabilities or misconfigurations in your SOAP, REST, or anything in between API that might put your company at risk.
It's important to not only get your product out and accessible, either to other teams at your company or even third-party consumers. Let us help you test your security and business logic to reduce any risk to both you and your clients.
Typical window – 1–2 weeks
Mobile Applications
Mobile applications have evolved past the days of "yoursite.com/mobile". With such a fast-paced push to reach the vast audience that mobile applications capture, security oftentimes comes in second or third on the priority list. With our identities almost tied to our phones, security can no longer be an afterthought.
We at 7Seas take on the challenge to help find those vulnerabilities not only client-side with iOS and Android applications from both a static and dynamic perspective, but we also dive deep into the server-side vulnerabilities. From bypassing client-side restrictions to business logic flaws in your API, we'll test your mobile app from a holistic perspective.
Typical window – 1–2 weeks
Thick Clients
Have a desktop or thick client application? We at 7Seas can take a deep dive into your application and attack from all angles with a multi-layered approach.
7Seas involves both static analysis of the client itself, using the latest static analysis tools on top of manual review, as well as dynamic analysis to discover how the application lives and breathes on the system. If your application communicates with a backend API, leave it to us to discover issues around OWASP Top 10, but also more intricate vulnerabilities such as business logic flaws and authentication/authorization issues and bypasses.
Typical window – 2–4 weeks
Generative AI-Powered Applications
Rolling out a feature powered by an LLM? Whether it's a chatbot inside your product, a RAG pipeline sitting on your internal documents, or an agent with access to real tools, we at 7Seas test the application from end-to-end. Benchmark scores and jailbreak demos tell you very little about what an attacker can actually do once that model is wired into your data and your APIs.
7Seas starts by mapping how data moves through your application: what reaches the context window, who is able to put it there, what the model is allowed to call, and what comes back. From there, we test the issues that don't disappear just because there's an LLM in the middle, like authentication and authorization flaws, business logic bypasses, and injection into whatever consumes the model's output. We pair that with the issues unique to GenAI: direct and indirect prompt injection through documents, pages, and tool responses; extraction of system prompts and other tenants' data out of a RAG corpus; tool and function call abuse, including chained calls the agent was never meant to make; and excessive agency where the model takes action with no human in the loop.
Typical window – 1–2 weeks
Internal Network Pentesting
Security does not stop and start at the perimeter. Internal network penetration testing gives you a review of your internal infrastructure from an attacker's perspective. Regardless of your infrastructure, we at 7Seas can test for vulnerabilities and security misconfigurations throughout the network so you can get a clear picture of your security posture.
Rather than send a tester on-site, 7Seas has seamless, deployable infrastructure ready to go either with your favorite container runtime or with virtualization software. Of course, if you prefer we connect to your VPN directly, we can cater to your specific needs and preferences. Prefer to go the hardware route than virtualization? We have plug-and-play devices at the ready with step-by-step instructions.
Typical window – 1 week
External Network Pentesting
We at 7Seas love cliches. Your security perimeter is only as strong as its weakest link. External network penetration testing encompasses testing the external attack surface of an organization and breaking that weak link. Our goal is to perform manual testing / attacks against external security controls, leveraging any available data externally accessible to attempt to gain a foothold into your internal network.
From leveraging Cloud services to targeting your externally-exposed, on-prem assets directly, we at 7Seas can assess your perimeter and give you a clear picture of how large your external footprint may be.
How an Engagement Typically Runs
-
Scoping Call
Thirty minutes with the tester who will perform the penetration test. We look at the application hollistically, work to gain a working understanding of the workflows and roles, and work to understand the risks to focus on.
-
Kickoff and Confirmation of Access
Credentials for every role, testing environment confirmed, and a shared communication channel established.
-
Testing, Reported Live
Criticals go to you the day we find them. We keep you in the loop at your preferred cadence and work with you during each step of testing.
-
Report and Walkthrough
Reproduction steps an engineer can follow, business impact a stakeholder can read, and a call to go through everything and anything.
Frequently Asked Questions
These are some questions we get very commonly from clients:
Is this just a scanner report with your logo on it?
No. Tooling runs at the start of an engagement to map surface area and nothing it produces reaches the report without a person confirming it, proving impact, and writing it up. However, our process is heavily manual with proven results. 7Seas testers have found findings on solutions that have been tested year after year by otheres.
What if you find nothing?
First off, great work building such a robust, secure application! In these instances, the report documents what was tested and what we observed you did right, and you have something defensible to hand an auditor or a customer. We would rather deliver honest coverage than pad a findings list with informational noise.
Who actually does the work?
The Senior+ tester on your scoping call. No handoff to someone you have never spoken to.
What sets you apart from others?
All of our testers are Senior+. We find findings on engagements that other companies do not. If you're curious on learning more about us, we have content on YouTube and Twitch. Watch a breakdown, then decide for yourself!
- Testing Model
- Manual, Senior-led
- Delivery
- Remote, worldwide
- Reporting
- OWASP mapped
Tell Us What Needs Testing.
Scoping calls are with a tester, not a salesperson.