Services

Security testing for the product.

Six engagement types for security-critical B2B products and platforms. Start with the physical or embedded product, the software platform around it, or a focused technical question. Scope follows product architecture and threat model.

Primary entry points

Start with what is actually in scope.

Is the physical or embedded product part of the target, or is the target the product software and platform?

02 / Product Pentest

Product Penetration Testing

Product software / platform in scope

Web and mobile applications, APIs, cloud-native backends, Kubernetes, management interfaces and network services that form part of the product.

To the service
Focused reviews

Cryptography, protocols and security-critical code.

Use a focused review when the technical question is narrower than a full product assessment.

03 / Cryptography Review

Cryptography Review

Cryptographic architecture, key management, signing, device identity, secure boot and protocol cryptography.

To the service
06 / Vulnerability Response

Vulnerability Response

Technical investigation of reported vulnerabilities and third-party CVEs, reproduction, exploitability, product impact, remediation support and retest.

On-demand response · Response retainer
To the service
TRIAGE REPRODUCE REMEDIATE VERIFY
Scoping

Scope. Attack & Review. Verify.

You do not need to map your problem to a Redlings discipline before the first conversation.

01

Scope with engineering

Map architecture, trust boundaries, attacker assumptions and the access needed for the assessment.

02

Attack & review

Use penetration testing, reverse engineering, protocol analysis, cryptographic review, source review or hardware analysis as required.

03

Findings and retest

Document reproducible findings, technical impact and remediation context, then verify fixes against the original attack path.

Scope. Attack & Review. Verify.

Tell us briefly what you need. We usually reply within one business day.

NDA first if required.