What we test
Every engagement — regardless of tier — is tested against the same fifteen categories. Grouped below by what they let an attacker actually do.
Attacks that get the target system to run code or logic it never should have.
Attacks that let someone act as a user they aren't, or do more than their role allows.
Weaknesses in what's exposed at the edge of your infrastructure, not just inside your application.
Whether personal data is reachable by anyone who shouldn't have it.
Automated tools flag matches, not vulnerabilities — and a raw match list is full of noise: paths that don't actually exist, logins that don't actually work, patterns that look dangerous but aren't reachable.
Every category above is checked by a person, not just a scanner. Where Hiraya surfaces a candidate, a tester confirms it's real — reproduces it, checks the impact, and only then writes it into your report. If we can't prove it, it doesn't ship as a finding; it goes in a separate notes section marked as unconfirmed, so you can see exactly what we did and didn't verify.
Pick a tier, tell us your scope, and we'll schedule the engagement.
See pricing