Penetration Testing for SaaS & Startups in Canada
Hands-on penetration testing for web apps, APIs, and cloud infrastructure. I've fixed 20+ vulnerabilities on a live platform serving 5,000+ users, and I found CVE-2024-45163, the Mirai botnet kill switch (CVSS 9.1). You get findings that matter, not a scanner dump.
Real testing, reports you can hand to customers.
Scanners catch the easy stuff. The problems that actually get companies breached are the ones a tool won't chain together: broken access control, IDOR, auth logic, a misconfigured cloud role. I test the way a real attacker would, then hand you a report your engineers can act on and a short attestation letter you can share with customers and partners.
I've built and broken the same kinds of systems you're shipping, so every finding comes with context and a fix that's realistic, not just a severity label.
Everything the engagement covers.
A clear path from where you are to done.
Scoping & rules of engagement
We agree on targets, test windows, and depth (black, grey, or white box) and set clear rules of engagement.
Testing
I manually test your applications, APIs, and infrastructure, chaining findings the way a real attacker would.
Reporting
You get an executive summary and a technical report with reproduction steps, impact, and fixes ranked by risk.
Remediation & retest
I support your team through fixes and retest the findings so you can prove they're closed.
Questions founders ask before we start.
What can you test?
Web applications, REST and GraphQL APIs, cloud infrastructure, and network perimeter. If you're not sure what's in scope, I'll help you define it.
Black box, grey box, or white box?
All three. Grey box (limited credentials/context) usually gives the best coverage per dollar for startups, but I'll recommend the right fit for your goals.
Will I get something I can share with customers?
Yes. You get a letter of attestation summarizing the engagement that satisfies vendor security reviews, plus the full technical report for your team.
How long does a pentest take?
Most startup engagements run 1–3 weeks depending on scope. You'll get a fixed scope and price before we start.
Does this satisfy SOC 2 or customer requirements?
Yes. A third-party pentest supports SOC 2 and ISO 27001 and clears the pentest requirement that shows up in most enterprise vendor security questionnaires.
Find the vulnerabilities before your customers' auditors do.
Tell me about your company and what's driving the timeline. I respond to every message personally.