ArpaCorp OPSEC — vulnerability assessment & penetration testing

Your systems believe they're secure.
We test whether that's true.

We run manual, adversarial security testing for businesses in the Philippines — three depths of engagement, one fixed rate card, every finding verified by a person before it reaches your report.

15
attack categories in every engagement
3
testing depths — blackbox, graybox, whitebox
1–2wk
typical turnaround per engagement

Why this matters
before it's mandatory

An attacker needs one working path in. You have to defend all of them. That asymmetry doesn't go away because a system has shipped without incident so far — it just means the gap hasn't been found yet, by someone willing to report it.

01

Clients and regulators are asking first

Enterprise procurement, banking partners, and government counterparties increasingly require independent test results before a contract is signed — not after an incident.

02

The Data Privacy Act makes exposure a liability, not just a risk

Under RA 10173, a leak of personal or personally identifiable information is a reportable event to the National Privacy Commission — testing for it in advance is cheaper than explaining it afterward.

03

Software changes faster than review cycles

Every new feature, integration, or third-party library is a new path in. A one-time review goes stale the moment the next deploy ships — which is why we offer retainers, not just point-in-time engagements.

How an engagement runs

01

Scope & rules of engagement

We agree on targets, testing windows, and what's off-limits before anything starts.

02

Reconnaissance & mapping

We map the real attack surface — including what you may not know is exposed.

03

Testing

Manual testing across all 15 categories, augmented by Hiraya for coverage and speed.

04

Verification

Every finding is manually confirmed. Nothing goes into your report on a scanner's word alone.

05

Reporting

Severity-ranked findings with reproduction steps and concrete remediation guidance.

06

Retest

Once you've fixed what we found, we confirm it's actually closed.

Built on Hiraya, our own testing platform

Hiraya means aspiration — the gap between what you believe about a system and what's actually true about it. It's also our name for the platform our own testers use on every engagement.

Hiraya isn't an autonomous scanner we point at your domain and walk away from. It gives our testers wider, faster coverage across an engagement — but every single finding it surfaces is manually verified by a person before it's written into your report. We've been burned before by tools that report a match and call it a finding; we don't ship that to clients.

How Hiraya works

Three depths, one rate card

Choose how much access we get before we start. More access finds more, faster — but even without credentials, we find what an outside attacker would.

Blackbox

Outside in

No credentials, no source. We test the way an opportunistic attacker would — from the outside, against what's actually exposed.

₱400,000 / engagement
Graybox — DAST

Authenticated depth

We're given working credentials and test every role and permission boundary from inside the application.

₱450,000 / engagement
Whitebox — SAST

Source-level review

Full repository access. We read the code, not just its behavior, and trace issues to the exact line.

₱550,000 / engagement

See full pricing, timelines, and retainer rates

Find out what's actually true

Tell us what you're running and we'll scope an engagement — blackbox, graybox, or whitebox, one-time or retainer.

Book an assessment