Vulnerability Assessment & Penetration Testing — Encrova
Services / VAPT
01 / OFFENSIVE SECURITY

Vulnerability assessment & penetration testing

Testing that produces evidence, not adjectives. Every finding is reproducible from the report alone, and we retest what your team remediates.

TYPICAL DURATION 2–4 weeks
PRICING Fixed, quoted on scope
RETEST Included
/ THE PROBLEM

Most organisations cannot say where they are exposed.

Estates grow by accretion. A supplier stands up a server, a team ships an internal tool, a firewall rule is added for a migration and never removed. The result is an attack surface nobody holds a complete picture of.

Automated scanning alone reports what is theoretically vulnerable. It does not tell you what an attacker could actually reach, chain together, or use to move laterally. That distinction is the difference between a list and a risk assessment.

/ OUR APPROACH
01

Scope in writing

Targets, exclusions, testing windows and escalation contacts agreed before anything is touched.

02

Discovery and mapping

The estate is enumerated as an attacker would see it, including assets you may not have on the register.

03

Manual exploitation

Findings are validated by hand and chained where chaining is possible. Anything critical is reported the same day.

04

Report, walkthrough, retest

A written deliverable, a session with your engineers, and a retest of everything remediated.

/ DELIVERABLES

What sits on your desk at the end.

DOCUMENT 01

Technical report

Each finding with reproduction steps, evidence, affected assets, CVSS rating and a remediation recommendation.

DOCUMENT 02

Executive summary

Two pages a board or an auditor can read: what was tested, what was found, what it means, what happens next.

DOCUMENT 03

Remediation tracker

Findings in priority order with owners and status, so remediation can be managed rather than remembered.

DOCUMENT 04

Retest certificate

Written confirmation of which findings were closed on retest — the document procurement and auditors ask for.

/ IN SCOPE
External and internal network testing
Web application and API testing
Cloud configuration review
Active Directory and identity review
Wireless and segmentation testing
/ SCOPED SEPARATELY
Social engineering and phishing simulation
Physical security assessment
Red team engagement with defined objectives
Source code review
Denial-of-service testing

Tell us what you want tested.

A rough asset count and the deadline you are working to is enough for us to come back with a scope and a fixed price.