POLKASPOTS

Penetration testing

You break it, you buy it. So let us break it first.

You're about to buy a company, ship a product, or answer a board. We try to break in first and tell you what we find — then work with the engineers to sort it out.

01

Traditional security reviews are broken. You get a 200-page report written by someone who's never touched a terminal. It's full of risk matrices and colour-coded tables. The deal closes. The report goes in a drawer. Six months later something blows up that was buried on page 147.

Compliance certifications mean someone filled in a form correctly. They don't mean the production database isn't open to the internet.

02

Flash Review

£500

Two hours, max velocity. We look at your public-facing stuff and find what's wrong. You get a plain-English report within 24 hours — what we found, how bad it is, what to do about it. If we find nothing worth worrying about, you don't pay.

LEARN MORE AND BUY →

Full Pentest

From £5,000

Proper thorough penetration test. Infrastructure, apps, APIs, cloud, code — everything that matters. Takes one to two weeks. Fixed price, scoped upfront so there are no surprises. You get a clear report with prioritised findings, full technical detail, and a plan to fix everything. You talk to the person doing the work, not a project manager.

Remediation

Scoped per engagement

We don't just find problems. We fix them. We work alongside your engineers to patch vulnerabilities, harden configurations, rotate credentials, sort out cloud permissions — whatever needs doing. This is what makes us different from everyone else in this space. Most security firms stop at the report. We keep going until it's actually sorted.

Ongoing Monitoring

Monthly retainer

For PE and VC firms with a portfolio. Continuous visibility into the security posture of your investments. We keep watching so you know when something's gone wrong before it becomes a headline. Regular testing, ongoing advice, and a direct line to someone who knows your systems.

03
01

Someone was about to put serious money into a SaaS company. We got into their entire customer database in four hours through a misconfigured API. Wasn't in the data room. Deal got renegotiated. We locked it down within a week of close.

02

PE firm buying a fintech platform. Production database was sitting on the open internet with default credentials. The company had a current ISO 27001 cert. We gave the buyer a plan to fix it before close and built the cost into the deal. Sorted within the first week.

03

Growth equity deal for an infrastructure company. Three critical unpatched holes in their customer-facing services, plus AWS keys hardcoded in a public GitHub repo. Seller had called their security posture “mature.” Keys rotated, services patched, proper secrets management in place within ten days.

04

Strategic acquisition of a crypto exchange. The technical docs said hot and cold wallets were segregated. They weren't. Material misrepresentation caught before close. Wallet architecture redesigned post-acquisition.

05

Token acquisition of a DeFi protocol. Found a reentrancy vulnerability in the core Solidity contracts that would let an attacker drain the liquidity pool. A well-known audit firm had signed off on them. Contracts rewritten and redeployed before the deal closed.

06

PE roll-up of a healthtech platform. Chained three weaknesses together — an open endpoint leaked an internal API, which leaked staff credentials, which got us into the patient records database. None of them looked critical on their own. Together they were devastating. Full chain closed within two weeks.

07

Late-stage VC round in a B2B SaaS company. Found an admin panel at a predictable URL with no login. Full tenant data for every customer — including the investor's own portfolio company. Found it in the first thirty minutes.

08

Strategic investment in a smart contract platform. The deployed contracts had privileged owner functions with no timelock and no multisig. One compromised key and all user funds were gone. Governance and key management overhauled after close.

These are representative. Real engagements are confidential.

04

If you're buying a company — or investing in one — and you want to know whether the tech is actually solid before you sign, talk to us.

We work with PE firms, VCs, M&A lawyers, corporate finance advisors and insurance underwriters — anyone in a deal who'd rather find out now than later. We also work directly with companies who want to know where they stand before a launch, an audit, or a customer security review.

BOOK A 30-MINUTE CALL

Or email us — same-day reply with a clear scope and a fixed price.

05