One run against your live product. Every finding proven with a working exploit, every fix verified by a second attack. We test only what you authorise.
A sample from real runs — on live products and authorised labs, target names withheld. Every item below was confirmed with a working exploit, not a scanner guess.
Any numeric user ID returned full profile data — date of birth, city, country, gender — with no login at all. It chained to a second open endpoint that dumped a whole membership list, making the entire user base enumerable.
Changing a single object ID in a request let one account read another account's private records — the flaw scanners miss because the response looks perfectly valid.
The real origin server was reachable directly behind the CDN/WAF — so rate-limits and bot rules could be walked around — alongside a weak content-security-policy and missing security headers.
A template-injection and a framework left in debug mode each opened a remote-code-execution path (Jinja2 SSTI and the Ignition / CVE-2021-3129 class) — full server reach from a single request.
Findings are anonymised and paraphrased. Every one was reproduced with a working exploit and human-reviewed before disclosure to the target.
You confirm you own the target, or hold written authorisation to have it tested. A scope you do not control is never accepted, and the scope gate is a deterministic rule — not a judgement call.
The agent reads and probes. Writes, deletions and anything persistent require an explicit flag and a second confirmation from you.
Proof is demonstrated with the smallest safe effect — a harmless echo, a canary, a boolean delta. No destructive commands, no binaries fetched, no persistence left behind.
Raw secrets stay out of the report and the logs — only the fact of exposure is recorded.
Rate limiting at ≤10 requests per second, timeouts, a circuit breaker on 5xx storms and an SSRF guard on internal addresses. You can stop a run at any moment.
One run produces one report: what was tested, what was proven, the recommended fix and the re-test result. Remediation is advised — your team applies it; the agent never writes to your code. See a sample report →
By ticking the box you agree that Sintropyc, acting as data controller, may process the personal data you enter in this form for the purposes set out below. This consent sits alongside our Privacy Policy and Data Processing Addendum, which set out the full detail.
Only what you submit here: your first and last name, your role or position, the website or system URL you want tested, your answer about server access, and anything else you add. If you go on to pay, card details are handled by our payment provider — we never receive or store full card numbers.
Only the Sintropyc team and the service providers we need to operate — such as Paddle for payments and the providers on our Subprocessor list. We do not sell your data, and we do not use it for marketing, model training, case studies or investor materials unless you give separate, specific consent first.
Only as long as needed for the purposes above. If you don't become a customer, we delete the request once the enquiry is closed; scan findings and reports are kept for up to 12 months unless we agree otherwise; billing and tax records are kept for as long as the law requires.
Consent is voluntary and you can withdraw it at any time, and ask to see, correct or delete your data, by emailing [email protected]. Withdrawing consent does not affect processing already carried out before you withdrew it.
Thanks — we've got your details and will get in touch shortly to confirm scope, price and next steps. Nothing is tested before you approve the scope in writing.