Request a proof scan

Tell us where to attack.

One run against your live product. Every finding proven with a working exploit, every fix verified by a second attack. We test only what you authorise.

01Your live data and secrets never reach the AI model — a strict data boundary keeps them out.
02Read-only by default. Destructive actions need an explicit flag.
03A written report: proof, remediation guidance, re-test, verdict.
04Checked by a person before it reaches you — never sent out on autopilot.
→See a full sample report · how it works
Scan request
Do you have access to the site's server?
Server access lets us mirror your stack exactly, so nothing surprises the run.
I accept all terms and conditions — authorised testing only, on a scope I own.
I consent to Sintropyc processing the personal data I enter here — for the purposes described here.
You pay $1,000
One fixed price — full test, proof of every finding, the exact fix and a re-test after you ship.
Accept the terms to continue
From real runs

What Sintropyc has already found.

A sample from real runs — on live products and authorised labs, target names withheld. Every item below was confirmed with a working exploit, not a scanner guess.

16
vulnerabilities confirmed with a working exploit
0
false alarms — unproven issues never reach the report
Confirmed, by class
IDOR / BOLA · 5 Unauthenticated PII / data · 3 Secrets & misconfig · 5 Injection → RCE · 3
Unauthenticated PII exposure Confirmed

Any numeric user ID returned full profile data — date of birth, city, country, gender — with no login at all. It chained to a second open endpoint that dumped a whole membership list, making the entire user base enumerable.

Broken object-level auth (IDOR / BOLA) Confirmed

Changing a single object ID in a request let one account read another account's private records — the flaw scanners miss because the response looks perfectly valid.

Security misconfiguration → WAF / origin bypass Confirmed

The real origin server was reachable directly behind the CDN/WAF — so rate-limits and bot rules could be walked around — alongside a weak content-security-policy and missing security headers.

Injection → remote code execution Confirmed · Critical

A template-injection and a framework left in debug mode each opened a remote-code-execution path (Jinja2 SSTI and the Ignition / CVE-2021-3129 class) — full server reach from a single request.

Findings are anonymised and paraphrased. Every one was reproduced with a working exploit and human-reviewed before disclosure to the target.