Penetration Testing Services
Assess an authorised application or environment for exploitable weaknesses and document what needs to be fixed. Rootscratch provides scoped penetration testing focused on practical evidence and remediation.
Define the workflow
Before testing, we agree in writing on assets, ownership, test accounts, permitted techniques, timing and stop conditions. Web applications, APIs and internal systems have different risk boundaries. Third-party systems require permission from their owner.
What the project can include
- Scope definition, environment preparation and rules of engagement.
- Manual examination of authentication, authorisation and application workflows.
- Controlled validation of findings with reproducible evidence.
- Prioritised reporting, remediation discussion and agreed retesting.
How we validate the result
Findings explain the affected workflow, prerequisites, observed impact and recommended correction. Testing uses approved accounts and minimises access to unrelated personal or business data. Potentially disruptive checks require an explicit agreed window.
Planning your project
Provide target assets, environments, user roles and the reason for the assessment. Black-box, authenticated and source-assisted reviews have different coverage. A test is a time-bounded assessment, not a guarantee that every vulnerability has been found.
Rootscratch is based in Koronadal City, Philippines, and works remotely with clients worldwide. Discuss your requirements to agree on deliverables, responsibilities, handover and ongoing support.