Start with the security decision
Make release, remediation and risk decisions using demonstrated results, explicit coverage and testable acceptance criteria.
We distinguish a scanner observation from a validated weakness, usable access from network reachability, and demonstrated impact from an untested possibility.
A public application, cloud workload and internal identity system may form one connected attack path. Scope those relationships deliberately, including third-party permissions, business rules and recovery dependencies.
An agreed scope, not an open-ended scan
We define the systems, identities, workflows and interfaces needed to answer the assessment objectives. Written authorisation, third-party permission, test accounts and an agreed data set come before active work. A proposal records exclusions and dependencies as well as inclusions.
- Web application penetration testing — Validate the business logic, sessions and access controls behind your application.
- API penetration testing — Test object ownership, service permissions and workflow state across API families.
- Network and Active Directory penetration testing — Examine reachable services, trust relationships and privileged access paths.
- Cloud penetration testing — Assess the authority exposed by cloud workloads, storage and deployment pipelines.
- Mobile application penetration testing — Review mobile clients alongside the APIs and identity services they use.
- Penetration test retesting — Validate that a specific fix closes the demonstrated path and preserves authorised use.
Questions the test can answer
- Can one customer or tenant read or modify another organisation’s records?
- Can a public application expose a workload identity with excessive internal authority?
- Do segmentation, approval and session-revocation controls stop the agreed attack path?
These are examples for scoping, not a claim that every engagement includes every method or system. The final test plan records the permitted actions, expected outcomes and observation needed to support each conclusion.
Operational safeguards are part of the method
Use written authorisation, agreed environments, synthetic data and named stop authority. Define rate limits, excluded methods, cleanup and escalation before testing. Production activity and supplier systems require explicit permission.
Testing can carry risk. Agree who can pause activity, which conditions trigger escalation and how genuine incidents are distinguished from exercise activity. No test is authorised by sending an enquiry through this website.
From findings to verified action
Receive an executive view, a scoped technical record, reproducible findings and a remediation register. Each finding should explain the observed result, the access or operation demonstrated, its limits and a practical acceptance test. Retest scope and timing are agreed in the statement of work.
Inspect the Meridian Group AG sample or review the deliverables before discussing your requirements.
Prepare a brief before the scoping call
Describe the decision you need to make, the systems involved and the boundaries the test must examine. The brief turns that context into proposed workstreams and questions for the scoping call.
Use the free penetration testing brief builder to record objectives, assessment areas, constraints and NDA preferences. Review the proposed scope, then send it directly to Atlant Security through the contact form.

