Skip to content Earthshaker Security Services Methodology Pricing Sample report FAQ About Book a scan

Four engagements. No packages you can't tell apart.

Each one below is a real body of work with a defined output. Pick the ones that match what you run — or send us the URL and we'll tell you which apply.

All of them produce the artifact a SOC 2, ISO 27001 or enterprise customer security review asks for: a dated report with a named tester, a written scope and a re-test record. We are not an auditor and we issue no certificate — we give you the evidence the auditor wants to see.

Web application penetration test

The core engagement
What it is

A human works through your application the way an attacker would: every input, every role boundary, every state transition. Automation sweeps first; the findings that matter come out of the manual pass.

What we find

Broken access control between users and roles, injection and XSS, authentication and session weaknesses, and business-logic abuse — discounts that stack, quantities that go negative, workflows that skip a step.

What the fix looks like

Usually a change in one layer: an ownership check moved into the data access path, escaping restored on output, a state machine that refuses illegal transitions. We name the file pattern, not just the vulnerability class.

API and endpoint testing

For anything with a mobile app or SPA
What it is

Your API is the real application; the UI is a suggestion. We test it directly — documented routes, undocumented routes, and the ones we find in your JavaScript bundle.

What we find

Object-level authorization gaps, mass assignment, missing rate limits, verbose errors, endpoints that were never meant to ship, and versioned routes that were deprecated in the docs but never switched off.

What the fix looks like

Authorization asserted per object rather than per route, explicit allow-lists on writable fields, and a rate-limit policy applied at the gateway so new endpoints inherit it by default.

External attack surface review

Start here if you have grown by acquisition or time
What it is

Everything the internet can see that belongs to you: hosts, subdomains, ports, certificates, cloud buckets, third-party embeds, exposed dashboards, and the things a previous developer left running.

What we find

Forgotten staging environments with production data, subdomains pointing at deprovisioned services and open to takeover, admin panels on non-standard ports, and credentials in public repositories or client bundles.

What the fix looks like

A prioritized decommission list, DNS records to remove, and access controls to put in front of what has to stay. Most of this work is deletion, which is the cheapest security you can buy.

Configuration and hardening audit

The cheap win most teams skip
What it is

A review of the settings around your application: TLS, security headers, cookie flags, CORS, storage permissions, email authentication and the defaults your platform shipped with.

What we find

Missing or permissive CSP and CORS, cookies without Secure or SameSite, over-broad bucket policies, SPF and DMARC that let anyone send mail as your domain, and debug settings alive in production.

What the fix looks like

A list of specific settings with the exact values to set, ordered by how much risk each one removes per minute of work. Most teams close this list in an afternoon.

Scope an engagement See what it costs Earthshaker Security

We find the cracks before they do. Automated and human-verified security testing for web applications.

earthshakersecurity.com · contact@earthshakersecurity.com

Earthshaker Security

Work
Services Methodology Pricing Sample report
If you're a…
Founder Shop or small business Developer or CTO Brand glyph in 3D ↗
Company
About FAQ Contact Disclaimer Report a vulnerability © 2026 Earthshaker Security Privacy Terms Disclaimer Cookie settings View all pages