How it works
Choose from the nine below, or from the menu.
Around fifteen to twenty short questions. Answer what you can — anything you are unsure of can be settled on the scoping call.
The scope and timeline update as you type. It is an indicative figure, confirmed with you on the scoping call.
Save your answers as Excel, or print to PDF, and email them to your SysTools contact.
Vulnerability Assessment and Penetration Testing
VAPTWe look for weaknesses in your systems and then safely prove what an attacker could actually reach. Each of these gives you an indicative number of days from the figures you enter.
Web Application VAPT
Your websites, portals and web-based software — logins, permissions and the logic behind the screens.
Estimate from application countStart scoping 02Mobile Application VAPT
Android and iOS apps — what they store on the phone, and how they talk to your servers.
Estimate from builds and screensStart scoping 03Network / Infrastructure VAPT
Your servers and network devices, and everything reachable on them from inside or outside your network.
Estimate from asset countsStart scoping 04API VAPT
The interfaces your other systems talk to. Permission gaps here are the most common serious finding.
Estimate from APIs and endpointsStart scoping 05IoT Device VAPT
Your connected devices — the hardware, the software inside them, and their wireless connections.
Estimate from device modelsStart scopingAudit & Assessment
Review, not attackWe review how your systems are built or set up and measure them against recognised standards. Nothing is exploited and nothing on your side is changed.
Cloud Security Assessment
Your AWS, Azure or GCP setup checked setting by setting against the standards you need to meet.
Estimate from accounts and servicesStart scoping 07Source Code Review
We read your source code and point at the exact line that needs changing.
Estimate from lines of codeStart scopingRed Teaming
Timeline agreed on the callGoal-led engagements that also measure whether your own team spots us. These are quoted after a conversation rather than from a form.
Red Teaming
A simulated attack working towards a real objective — and a timeline of what your team detected.
Typically 3–8 weeksStart scoping 09AI Red Teaming
Your chatbots, agents and scoring models — can they be made to leak data, ignore their rules or act for an attacker?
Typically 1–4 weeksStart scoping