SERVICES

Six products. Fixed scope, fixed price, fixed date.

Every product ends in the same deliverable: one report, reviewed by a second engineer, delivered on the date in the contract — or you pay ten percent less.

RECON · 4 DAYS

Basalt Recon

One full attack path, outside in. A page for your board, a technical chapter for your engineers. The right first engagement if you have never been tested — or never been told the truth.
from €2 500
PROBE · 8 DAYS

Basalt Probe

Web applications and APIs, fixed scope, manual testing. The report your client's procurement asks for — and the retest certificate that closes the deal.
from €6 000
PIPELINE · 10 DAYS

Basalt Pipeline

Cloud, CI/CD and supply chain. Infrastructure as code, secrets, artefacts, role chains — the way an attacker reads your build, not the way your diagram draws it.
from €9 000
PROOF · 10 DAYS

Basalt Proof

Validation of your SOC or MDR. Eight to ten ATT&CK scenarios against your live detection stack. You learn what fires, what is logged silently, and what passes unseen.
from €10 000
RECORD · RETAINER

Basalt Record

Quarterly retest and continuous attack-surface monitoring, with evidence your auditor accepts. The cheapest way to keep last quarter's fixes fixed.
from €1 000/mo
RANGE · 2–3 DAYS

Basalt Range

Hands-on training. Your engineers break a deliberately vulnerable application, then fix it. Nobody forgets a vulnerability they exploited themselves.
from €3 000
EXTENSION · AI IN YOUR PRODUCT

You shipped an agent. We find what it can be talked into.

Prompt injection, tool abuse, retrieval that ignores your permission model, and the supply chain behind the weights. Sold as a three-to-five-day extension to Probe or Pipeline. There is no separate "AI security" product — and no AI writing your report.

DEEP DIVES
penetration-testing red-teaming social-engineering cloud-security ci-cd-security llm-security security-training

Everything we do, in the words you would search for

OFFENSIVE TESTING
External perimeter · internal network and Active Directory · web · API · mobile · adversary simulation · purple team · social engineering and phishing · OSINT and organisational footprint · attack surface monitoring
CLOUD, PIPELINE, SUPPLY CHAIN
AWS · Azure · GCP · Kubernetes and containers · CI/CD · infrastructure as code · secrets and key management · privilege chains and identity federation
AI, TRAINING, ASSURANCE
LLM application testing · ML supply chain · secure development workshops · social-engineering resilience · blue-team attack-chain review · quarterly retest and auditor evidence

Not sure which one? Start with Recon.

Four days, fixed price. If a bigger engagement follows within ninety days, the Recon fee counts toward it.

Book a 4-day Recon