United Kingdom practice GBP invoices GMT / BST hours CMA 1990 authorisation Retest included Letter of attestation on request

Operator-led penetration testing

The pentest a UK buyer can put in a board pack.

Manual testing of web, API, mobile, cloud and network. Two authenticated identities. Every finding with a replayable proof. Mapped to OWASP, ISO 27001 and NCSC CAF where the mapping is honest. Invoices in pounds sterling.

Who this is for

Built for UK product companies. Not a CHECK mill.

UK procurement at banks and CNI will ask for CREST or NCSC CHECK. We do not hold those memberships, and we will not print the logos. If that is a hard gate, we are the wrong supplier — we will tell you on the first call. If you need the tester who already reports P1s to Samsung and Binance, on UK hours, with a report your customer’s security team can replay, that is this practice.

A fit

UK SaaS and fintech selling into enterprise. Agencies whose end-client asked for a VAPT report. Product teams that need two-account proof, not a Nessus PDF, before a SOC 2 / ISO / CE+ questionnaire.

Not a fit

CHECK-mandated CNI, CBEST/TIBER red team, or a tender that names CREST as a condition of contract. Those buyers should use a CREST member. We will say so rather than stretch the truth.

Typical engagement

Scoped in a call. Priced in GBP. Signed before a packet is sent.

Dates lock on the scoping call. Destructive checks stay out unless you write them in. A re-test of every confirmed issue is included.

SurfaceUsual window
Web application3–5 working days
API (REST / GraphQL)4–7 working days
Mobile (Android / iOS)4–7 working days
Cloud (AWS / Azure / GCP)1–2 weeks
Internal / Active Directory1–2 weeks

Method

Six steps from first call to signed-off fixes

Written authorisation under the Computer Misuse Act 1990 before a packet is sent. No scope creep. A re-test at the end.

01

Scoping & authorisation

In-scope hosts, identities, hours, and a signed authorisation letter so the work is lawful in the UK.

02

Reconnaissance

Map what is actually exposed — subdomains, logins, APIs, forgotten staging — often including assets the team no longer remembers.

03

Vulnerability discovery

Feature-by-feature manual testing, with professional tooling as a force multiplier, not a substitute.

04

Exploitation & proof

Every finding ships with a reproducible proof. You will be able to replay it on your laptop.

05

Reporting

Executive one-pager plus a full technical write-up. Mapped to OWASP, ISO 27001 and NCSC CAF outcomes where they apply.

06

Remediation & re-test

You patch. We re-test every confirmed issue, for free, and issue a sign-off letter for customers and auditors.

Full methodology

United Kingdom

Built for UK product and security teams

UK buyers do not want a Nessus PDF. They want evidence that stands up in a Cyber Essentials Plus review, an ISO 27001 Stage 2, a PCI ROC, or an enterprise security questionnaire.

Reports UK reviewers will open

Findings mapped to OWASP, ISO/IEC 27001 Annex A and NCSC CAF objectives. CVSS v3.1. Signed letter of attestation you can attach to procurement.

UK hours, GBP invoices

Calls during GMT/BST office hours. Same-day replies on working days. Quotes and invoices in pounds sterling. VAT treatment confirmed in the statement of work.

Lawful UK testing

Every job starts with a signed authorisation letter covering the Computer Misuse Act 1990. NDA on request. Data deleted after close, report retained as agreed.

London, nationwide, remote-default

Most work is remote. When it helps we will sit with your engineers in London or another major UK city for scoping, a workshop, or a findings debrief.

Practice lead

Hassan Jawaid

VAPT.UK is led by Hassan Jawaid. Five-plus years of legal offensive work on bug bounty programmes, three-plus years delivering professional penetration tests. The same adversary mindset, now as a UK practice.

Over 1,000 real bugs reported to companies including Samsung, Binance, cPanel, F5, Ubisoft and SAP. Your engagement gets that attention — attacker paths, not a scanner dump.

  • ISO/IEC 27001 Information Security Associate — Skillfront (Aug 2022)
  • AppSec Practitioner certified
  • Penetration Tester / Ethical Hacker at Cubix — Jun 2022 to present
  • DevSecOps consultant — Vaival Technologies (2023)
  • BS Computer Science — Sir Syed University of Engineering & Technology
ISO/IEC 27001AppSec Practitioner 89.3% Bugcrowd accuracy
The Palace of Westminster and Elizabeth Tower from the Thames at dusk.
London. Scoped, billed and reported for UK buyers.

Platform rankings

#465
Bugcrowd · 1,189 pts · 89.3% acc.
#406
YesWeHack
#33
Bug Bounty Switzerland
#308
HackenProof

P1 Warrior Level 2 · Bounty Bee Level 7 · Submission Shogun Level 8 · MVP of October 2020 · Top Performer at Cubix, 2023 & 2024.

56+ security halls of fame — Samsung, Walmart, SAP, Atlassian, Deutsche Bank, Ubisoft, Binance and more.

Recognized by the best

In the security Hall of Fame of leading organisations

Responsibly disclosed vulnerabilities, publicly acknowledged — Fortune 500s, banks, and government programmes. The same operator runs every VAPT.UK engagement.

Samsung logo
Walmart logo
SAP logo
Atlassian logo
Deutsche Bank logo
Ubisoft logo
Trend Micro logo
Binance logo
Etsy logo
Sophos
Lenovo logo
Fitbit logo
ExpressVPN logo
GoPro logo
Bethesda logo
Indeed logo
Gusto logo
Acorns logo
DraftKings logo
Keeper Security
Webflow logo
Segment logo
Cloudinary logo
Office Depot
IBM logo
Avira
Bitstamp logo
Qlik logo
Iterable
Navan
Paycor
CallRail
Aiven
Postmark
Instructure
Movember
Zola
ImageKit logo
YNAB logo
+17 more
U.S. Homeland SecurityGen DigitalConvertKitRoktPeakonExoscalePeople.aiMovember FoundationCredit KudosAmpolJoraLetgoSnapNamesKiwigridSplashIDYatOctopusNeeva

FAQ

Common questions

What UK teams usually ask before they book.

VAPT is a structured attempt to break your systems, prove the holes, and tell you how to close them — before a criminal or a customer’s pentester does. UK organisations commission it for Cyber Essentials Plus, UK GDPR due diligence, ISO 27001, PCI DSS, and enterprise security questionnaires.
Most UK work is remote during GMT/BST hours. On-site scoping, workshops and debriefs can be arranged in London and other major UK cities when the engagement needs it.
We do not currently hold CREST or NCSC CHECK membership, and we will not pretend otherwise. What you get is a manual-first test with CVSS, reproducible proof, ISO 27001 / NCSC CAF mapping, and a free re-test — the packet most UK auditors and procurement teams actually read.
Focused web application: 3–5 working days. Mobile or API: 4–7 days. Cloud or internal network: 1–2 weeks. Dates are agreed on the scoping call before any contract is signed.
A five-minute executive summary, a full technical report (severity, screenshots, exact steps, fix), a free re-test after you patch, and a letter of attestation on request.
Yes. We issue a signed authorisation letter covering the Computer Misuse Act 1990. NDA on request. We only touch what you signed off. After close we delete collected data and retain the report as agreed.

Contact

Start a conversation

Tell us the product, the environment, and the UK compliance driver. We reply within UK working hours — usually the same day.

pentest@vapt.uk

United Kingdom · London & nationwide · remote-default

Written authorisation under the Computer Misuse Act 1990 before any testing starts. NDA on request.