SERVICES

Six assessment formats with clear boundaries, price and delivery date.

Each one ends with a reviewed report, an agreed retest period and delivery on the date stated in the contract.

RECON · 4 DAYS

Basalt Recon

One agreed route to potential impact, assessed from the outside in. You receive a concise view for decision-makers and technical evidence for the team that will act.
from €2 500
PROBE · 8 DAYS

Basalt Probe

Manual assessment of web applications and APIs within agreed engagement boundaries, with a report and retest confirmation for your records.
from €6 000
PIPELINE · 10 DAYS

Basalt Pipeline

Cloud, CI/CD and supply-chain assessment of infrastructure as code, secrets, artefacts and identity paths that could lead to production impact.
from €9 000
PROOF · 10 DAYS

Basalt Proof

Controlled validation of SOC or MDR detection and response against eight to ten agreed ATT&CK scenarios. You see what is detected, escalated, contained or missed.
from €10 000
RECORD · RETAINER

Basalt Record

Quarterly retesting and continuous monitoring of agreed external exposure, with evidence that shows whether remediation remains effective.
from €1 000/mo
RANGE · 2–3 DAYS

Basalt Range

Hands-on training where engineers identify and remediate vulnerabilities in a deliberately vulnerable application.
from €3 000
EXTENSION · AI IN YOUR PRODUCT

AI security as an extension to the product you operate.

We assess prompt injection, tool use, retrieval permissions and AI supply-chain risks in the systems you run. It is a three-to-five-day extension to Probe or Pipeline; the focus is product security, not generic model scoring.

DEEP DIVES
penetration-testing red-teaming social-engineering cloud-security ci-cd-security llm-security security-training

Everything we do, in the words you would search for

OFFENSIVE TESTING
External perimeter · internal network and Active Directory · web · API · mobile · adversary simulation · purple team · social engineering and phishing · OSINT and organisational footprint · attack surface monitoring
CLOUD, PIPELINE, SUPPLY CHAIN
AWS · Azure · GCP · Kubernetes and containers · CI/CD · infrastructure as code · secrets and key management · privilege chains and identity federation
AI, TRAINING, ASSURANCE
LLM application testing · ML supply chain · secure development workshops · social-engineering resilience · blue-team attack-chain review · quarterly retest and auditor evidence

Not sure where to begin? Start with Recon.

Four days, fixed price. If a larger engagement follows within ninety days, the Recon fee is credited toward it.

Discuss an assessment