VECTORUM · Offensive security · Prague

Penetration testing · Red teaming · Security research

We find the vulnerabilities that lead to real compromise.

We test the security of web applications, infrastructure and internal systems from the perspective of a real attacker. We focus on what an attacker can actually reach, what that would cost you, and how to fix it.

What we test

We build every engagement around real risk: what an attacker can reach, how they get there, and what matters most to fix first.

WEB

Web application testing

OWASP Top 10, business logic, authentication, API endpoints, session management, access control.

API

API & GraphQL security

Authorization, introspection, rate limiting, IDOR, mass assignment, schema abuse and abuse-case testing.

INFRA

Infrastructure and networks

External and internal infrastructure, Active Directory, cloud configuration, segmentation and network services.

MOBILE

Mobile applications

Android and iOS, local storage, API communication, deep links, build configuration and runtime behavior.

RED

Red teaming

Realistic attack simulation, detection testing, phishing scenarios by agreement, and validation of the SOC response.

CODE

Code review

Security audit of source code, review of critical flows, cryptography, authentication and the data layer.

How we work together

01

Scope call

We agree on goals, scope, how intrusive the testing can be, contacts, and the rules for safely proving impact.

02

Testing window

We test manually and with tooling, report critical findings as we go, and keep a full audit trail.

03

Report & retest

You get a clear report with evidence, priorities, remediation guidance and the option of a follow-up retest.

Let's talk about your project

Not sure exactly what you need? Tell us roughly what you have and we'll work out the scope together.
The form goes straight to our mailbox; if you'd rather talk it through, call +420 606 369 054.