
Healthcare →
Patient portals, EHR integrations and ransomware resilience.
Example finding
Portal returns other patients' lab results when the record ID changes
ZW-Labs · Penetration testing + 24/7 managed SOC
We attack your web apps, APIs, cloud and networks the way a real adversary would — then our SOC watches them around the clock. One team, both sides of the fence.
Any signed-in customer can read any other customer's invoices
Evidence
GET /api/v2/invoices/48213
Authorization: Bearer
→ 200 OK · invoice belongs to tenant 7731Fix
Check the invoice's tenant against the caller's on every read, and add a regression test that fails if the check is removed.
01
One standard for every engagement: every finding is reproducible, and every fix is retested.
We test the app your customers log in to, across every role, the way someone who wants their data would.
Any signed-in customer can read any other customer's invoices
APIs expose your data model directly. We test every endpoint — documented or not — for what it gives away.
Setting "role": "admin" on a profile update is accepted
An LLM feature is a new way into your systems. We test what it can be made to say, reveal and do.
A shared document makes the assistant email its contents to an outsider
Most cloud breaches start with a setting, not an exploit. We find the ones that actually lead somewhere.
A CI role can assume the production admin role
A mobile app ships your client code to every attacker who downloads it. We test the app and what it talks to.
Session token written to the device log in plain text
From the internet we find what's exposed. From inside we show how far one compromised laptop gets.
A backup service account's password is crackable offline
02
You always know what is being tested, by whom, and when. Nothing is touched until scope and written authorisation are agreed.

Before we start
Scope
We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.
During the test
Test
Hands-on testing. Anything critical comes to you the day we find it, not in the final report.
When testing ends
Report
An executive summary for leadership, and every finding with evidence, severity and a specific fix.
When you're ready
Retest
We verify each fix and reissue the report showing what's closed — ready for auditors and customers.

03 — The night shift
Analysts triage every alert from the tools you already run, around the clock. When it's real, we contain it with you — and explain what happened in plain English.
Explore managed SOC →04 — Sectors · 06:00
Each sector is attacked differently. We start from how yours is attacked, not from a checklist.

Healthcare →
Patient portals, EHR integrations and ransomware resilience.
Example finding
Portal returns other patients' lab results when the record ID changes

SaaS →
Tenant isolation, public APIs and the evidence your customers ask for.
Example finding
Organisation admin can invite themselves into any other tenant

Fintech →
Payment logic, account takeover and partner APIs.
Example finding
Race condition credits a single transfer twice

Insurance →
Policyholder data, claims portals and broker access.
Example finding
Claim documents downloadable by guessing a sequential ID
05 — Start
A few lines is enough to scope it. We reply with questions or a written proposal.
Or email [email protected]
Under attack now? Put "INCIDENT" in the subject.