Penetration Testing · Canada

Penetration Testing for SaaS & Startups in Canada

Hands-on penetration testing for web apps, APIs, and cloud infrastructure. I've fixed 20+ vulnerabilities on a live platform serving 5,000+ users, and I found CVE-2024-45163, the Mirai botnet kill switch (CVSS 9.1). You get findings that matter, not a scanner dump.

76control SOC 2 Type II program built at Humera
20+client security & compliance engagements
9.1CVSS, CVE-2024-45163, Mirai kill switch
5,000+users on a live platform I secured

Real testing, reports you can hand to customers.

Scanners catch the easy stuff. The problems that actually get companies breached are the ones a tool won't chain together: broken access control, IDOR, auth logic, a misconfigured cloud role. I test the way a real attacker would, then hand you a report your engineers can act on and a short attestation letter you can share with customers and partners.

I've built and broken the same kinds of systems you're shipping, so every finding comes with context and a fix that's realistic, not just a severity label.

Everything the engagement covers.

Web application penetration testing (OWASP-aligned)
REST and GraphQL API security testing
Cloud and infrastructure configuration review (AWS, GCP, Cloudflare)
Authentication, authorization, and access-control testing
Executive summary plus a detailed technical report
Prioritized, actionable remediation guidance
Free remediation retest to confirm fixes
Letter of attestation for customer security reviews

A clear path from where you are to done.

Scoping & rules of engagement

We agree on targets, test windows, and depth (black, grey, or white box) and set clear rules of engagement.

Testing

I manually test your applications, APIs, and infrastructure, chaining findings the way a real attacker would.

Reporting

You get an executive summary and a technical report with reproduction steps, impact, and fixes ranked by risk.

Remediation & retest

I support your team through fixes and retest the findings so you can prove they're closed.

Questions founders ask before we start.

What can you test?

Web applications, REST and GraphQL APIs, cloud infrastructure, and network perimeter. If you're not sure what's in scope, I'll help you define it.

Black box, grey box, or white box?

All three. Grey box (limited credentials/context) usually gives the best coverage per dollar for startups, but I'll recommend the right fit for your goals.

Will I get something I can share with customers?

Yes. You get a letter of attestation summarizing the engagement that satisfies vendor security reviews, plus the full technical report for your team.

How long does a pentest take?

Most startup engagements run 1–3 weeks depending on scope. You'll get a fixed scope and price before we start.

Does this satisfy SOC 2 or customer requirements?

Yes. A third-party pentest supports SOC 2 and ISO 27001 and clears the pentest requirement that shows up in most enterprise vendor security questionnaires.

Find the vulnerabilities before your customers' auditors do.

Tell me about your company and what's driving the timeline. I respond to every message personally.