Find every vulnerability before an attacker does.

Penetration testing for Web2, Web3 and AI systems - delivered by a vetted network of 400+ white-hat hackers, peer-reviewed by independent auditors, and aligned with the compliance frameworks you need to satisfy.

Global Brands That Trust AuditOne

400+
Vetted white-hat hackers in our network
4x
Independent auditors peer-review every report
8+
Target environments - web, mobile, cloud, smart contracts and more
24h
Average turnaround from request to quote
how we are different

Most pentest firms send one tester. We send four.

A single pentester sees what they know. Four independent pentesters see what an attacker would.
Every AuditOne engagement is conducted by 3 to 4 independent white-hat hackers working in parallel on the same scope. They do not communicate during the test. They compile their findings separately. Then they peer-review each other's work to produce a single consolidated report.

The result: dramatically broader vulnerability coverage, fewer false positives, and findings that have been validated by more than one expert before they ever reach your inbox.
Independent parallel testing — multiple attack surfaces explored simultaneously, by people who think differently.
Cross-validation of findings — every issue confirmed by at least two auditors before it appears in your report.
Skin in the game — our hackers receive a bonus for every valid vulnerability they discover, incentivising depth over checklist completion.
services

What we test.

Comprehensive coverage across the modern attack surface — from your customer-facing web app to your smart contracts to the AI model serving your users.
Web Application
OWASP Top 10, business logic flaws, authentication bypasses, injection vectors. Black-box, grey-box, or white-box engagement.
WEB 2
API Pentesting
REST, GraphQL, gRPC. Authorisation gaps, IDOR, rate-limit bypass, schema introspection abuse. OWASP API Security Top 10.
WEB 2
Mobile Application
iOS and Android. Reverse engineering, certificate pinning, insecure storage, runtime manipulation, OWASP MASVS-aligned testing.
WEB 2
Infrastructure
External and internal network testing, Active Directory abuse, lateral movement, privilege escalation paths to crown jewels.
WEB 2
Cloud Pentesting
AWS, Azure, GCP. IAM misconfigurations, exposed services, container escape, serverless attack chains, cross-account access.
WEB 2
Smart Contract
Solidity, Vyper, Rust (Solana, NEAR). Reentrancy, oracle manipulation, MEV exposure, access control, economic exploits.
WEB 3
Blockchain Infrastructure
Node configurations, consensus participation, bridge security, custodial wallet flows, key management ceremonies.
WEB 3
AI / LLM Systems
Prompt injection, jailbreaking, training-data extraction, model inversion, RAG-context poisoning. OWASP LLM Top 10.
WEB 3
Browser Extensions
Manifest V2/V3, content-script isolation, privilege boundary abuse, malicious update vectors, supply-chain exposure.
Specialised
pricing

Pay for what we find. Not what we don't.

An incentive structure that aligns with you.
Traditional pentest firms charge a flat day rate regardless of what they discover. Our hackers earn a base fee plus a per-finding bonus tied to severity. The cleaner your code, the lower your final invoice. The dirtier your code, the more thorough your test — and the more findings you get to fix before the attackers do.

Either way, the incentive is the same: find every real issue, document it properly, and don't pad the report with noise. Every finding goes through peer review before it makes it into your invoice or your report.
↓ 30%
Typical engagement cost reduction when your codebase has fewer than expected findings.
how it works

From request to final report in 2 to 4 weeks.

01
Scope & quote
within 24 hours
Share your codebase, repository, or environment details. We confirm scope, methodology (PTES, OWASP, MITRE ATT&CK as applicable), and engagement type. You receive a fixed-floor quote with the per-finding bonus structure spelled out.
02
Meet your team
2 to 3 days
We assemble a team of 3–4 vetted, certified pentesters matched to your target environment and threat model. You see their certifications and prior engagement domains before they are confirmed. Deposit secured, NDA signed, off they go.
03
Parallel testing
1 to 3 weeks
Each hacker works independently against the agreed scope. Automated tooling baselines common vulnerabilities; manual testing surfaces the business-logic and chained-exploit findings that automation misses. Critical findings are surfaced immediately, not held until the final report.
04
Peer review & consolidation
3 to 5 days
The team convenes. Every finding is reviewed by at least one auditor who did not discover it. Duplicates are merged, false positives are filtered, and severity ratings (CVSS 3.1 or industry-appropriate equivalent) are agreed. One report, four signatures.
05
Remediation & retest
Engagement-dependent
Preliminary report delivered with remediation guidance. Your team patches. We retest specifically the closed issues at no additional cost (within 30 days) and issue the final, certification-ready report for your compliance file.
compliance

Reports written to be accepted.

Our deliverables are formatted to satisfy the evidence requirements of every major security framework your auditors will check. One pentest, multiple compliance use cases.
ISO/iec 27001

Information Security

Annex A.8.8: Management of technical vulnerabilities
Independent pentest evidence accepted by certification bodies as primary support for control implementation.
SOC 2

Trust Services Criteria

CC7.1: System monitoring
Annual pentest report referenced in CPA audit working papers, with retest evidence for remediated findings.
PCI DSS 4.0

Cardholder Data Environment

Requirement 11.4: External & internal pentesting
Methodology compliant with PCI guidance, segmentation testing supported, QSA-ready report format.
DORA

EU Digital Operational Resilience

Article 24-27: TLPT-aligned testing
Threat-led penetration testing for financial entities, aligned to TIBER-EU framework where required.
NIS2

EU Cybersecurity Directive

Article 21: Risk management
Vulnerability testing evidence for essential and important entities under national NIS2 transposition.
HIPAA - GDPR

Healthcare & Privacy

Article 32:   Security Rule
"State of the art" security testing evidence, structured to satisfy data-protection authority inquiries.
feedback

What clients say.

FAQs

How do I prepare for a penetration test?

Three things help most: a clear scope document listing the assets to be tested, a test environment isolated from production where possible (or a maintenance window if production is in scope), and an internal point of contact who can respond to questions during the engagement. For Web3, share the repository commit hash you want tested and any deployment addresses. For AI/LLM systems, share the system prompt and any RAG sources. We provide a scoping checklist after the first call.

How long does a pentest take?

Most engagements run 2 to 4 weeks end-to-end. A small single-application scope can close in 1–2 weeks. A complex multi-environment engagement (web + API + cloud + AD) typically takes 3–4 weeks of testing followed by 3–5 days of peer review and consolidation. Smart contract audits are scoped by code complexity rather than duration — we quote both.

How is the price calculated?

A fixed-floor base fee covering the scoping, four auditors' base time, peer review, and report production — plus a per-finding bonus weighted by severity (Critical / High / Medium / Low / Informational, CVSS 3.1). The bonus structure is disclosed in your quote so you can model the upper bound. In practice, engagements typically land 10–30% below the cap because not every codebase has a long tail of medium and low findings. You can also use our price calculator for an indicative range.

What methodology do you follow?

For web and infrastructure: PTES (Penetration Testing Execution Standard) and OWASP testing guides as the backbone, MITRE ATT&CK for adversary emulation when relevant. For mobile: OWASP MASVS and MSTG. For APIs: OWASP API Security Top 10. For smart contracts: a hybrid of SWC Registry, Trail of Bits' "Building Secure Contracts", and our internal Web3 checklist. For AI/LLM systems: OWASP LLM Top 10 and MITRE ATLAS. The applicable methodology is named in your engagement letter and your final report.

Will the report satisfy our certification body?

Yes. Our reports are written to the format that ISO 27001 certification bodies, SOC 2 CPA firms, PCI QSAs, and DORA-supervisory authorities expect to receive. They include executive summary, methodology, scope, findings with CVSS scoring and remediation guidance, evidence appendices, and retest verification of closed items. If your specific auditor has a custom format requirement, share it during scoping and we will accommodate.

Is the retest included?

Yes, for findings remediated and resubmitted within 30 days of the preliminary report. The retest specifically verifies closure of the reported issues — it is not a fresh end-to-end engagement. If new functionality has been deployed since the original test and you want it covered, that is a scope extension at the per-finding bonus rate (without the fixed base fee).

Do you do red-team or adversary-emulation exercises?

Yes, separately from standard pentesting. Red-team engagements have different scoping, longer timelines (typically 4–8 weeks), and a different deliverable focus (blue-team detection and response capability) compared to vulnerability-focused pentests. For DORA TLPT and TIBER-EU engagements specifically, ask for our threat-led testing brief.

What if a critical vulnerability is found during testing?

It is escalated to your engagement point of contact within hours, not weeks. We do not sit on critical findings until the final report. You receive a preliminary write-up with reproduction steps and an immediate mitigation recommendation so your team can act before the testing window even closes.