ArpaCorp OPSEC — vulnerability assessment & penetration testing
We run manual, adversarial security testing for businesses in the Philippines — three depths of engagement, one fixed rate card, every finding verified by a person before it reaches your report.
An attacker needs one working path in. You have to defend all of them. That asymmetry doesn't go away because a system has shipped without incident so far — it just means the gap hasn't been found yet, by someone willing to report it.
Enterprise procurement, banking partners, and government counterparties increasingly require independent test results before a contract is signed — not after an incident.
Under RA 10173, a leak of personal or personally identifiable information is a reportable event to the National Privacy Commission — testing for it in advance is cheaper than explaining it afterward.
Every new feature, integration, or third-party library is a new path in. A one-time review goes stale the moment the next deploy ships — which is why we offer retainers, not just point-in-time engagements.
Choose how much access we get before we start. More access finds more, faster — but even without credentials, we find what an outside attacker would.
No credentials, no source. We test the way an opportunistic attacker would — from the outside, against what's actually exposed.
We're given working credentials and test every role and permission boundary from inside the application.
Full repository access. We read the code, not just its behavior, and trace issues to the exact line.
Hiraya means aspiration — the gap between what you believe about a system and what's actually true about it. It's also our name for the platform our own testers use on every engagement.
Hiraya isn't an autonomous scanner we point at your domain and walk away from. It gives our testers wider, faster coverage across an engagement — but every single finding it surfaces is manually verified by a person before it's written into your report. We've been burned before by tools that report a match and call it a finding; we don't ship that to clients.
We agree on targets, testing windows, and what's off-limits before anything starts.
We map the real attack surface — including what you may not know is exposed.
Manual testing across all 15 categories, augmented by Hiraya for coverage and speed.
Every finding is manually confirmed. Nothing goes into your report on a scanner's word alone.
Severity-ranked findings with reproduction steps and concrete remediation guidance.
Once you've fixed what we found, we confirm it's actually closed.
Tell us what you're running and we'll scope an engagement — blackbox, graybox, or whitebox, one-time or retainer.
Book an assessment