A fit
UK SaaS and fintech selling into enterprise. Agencies whose end-client asked for a VAPT report. Product teams that need two-account proof, not a Nessus PDF, before a SOC 2 / ISO / CE+ questionnaire.
Operator-led penetration testing
Manual testing of web, API, mobile, cloud and network. Two authenticated identities. Every finding with a replayable proof. Mapped to OWASP, ISO 27001 and NCSC CAF where the mapping is honest. Invoices in pounds sterling.
Who this is for
UK procurement at banks and CNI will ask for CREST or NCSC CHECK. We do not hold those memberships, and we will not print the logos. If that is a hard gate, we are the wrong supplier — we will tell you on the first call. If you need the tester who already reports P1s to Samsung and Binance, on UK hours, with a report your customer’s security team can replay, that is this practice.
UK SaaS and fintech selling into enterprise. Agencies whose end-client asked for a VAPT report. Product teams that need two-account proof, not a Nessus PDF, before a SOC 2 / ISO / CE+ questionnaire.
CHECK-mandated CNI, CBEST/TIBER red team, or a tender that names CREST as a condition of contract. Those buyers should use a CREST member. We will say so rather than stretch the truth.
Typical engagement
Dates lock on the scoping call. Destructive checks stay out unless you write them in. A re-test of every confirmed issue is included.
| Surface | Usual window |
|---|---|
| Web application | 3–5 working days |
| API (REST / GraphQL) | 4–7 working days |
| Mobile (Android / iOS) | 4–7 working days |
| Cloud (AWS / Azure / GCP) | 1–2 weeks |
| Internal / Active Directory | 1–2 weeks |
Services
A human goes through the product feature by feature. Scanners are support, not the engagement.
02
03
04
05
06
07
Method
Written authorisation under the Computer Misuse Act 1990 before a packet is sent. No scope creep. A re-test at the end.
In-scope hosts, identities, hours, and a signed authorisation letter so the work is lawful in the UK.
Map what is actually exposed — subdomains, logins, APIs, forgotten staging — often including assets the team no longer remembers.
Feature-by-feature manual testing, with professional tooling as a force multiplier, not a substitute.
Every finding ships with a reproducible proof. You will be able to replay it on your laptop.
Executive one-pager plus a full technical write-up. Mapped to OWASP, ISO 27001 and NCSC CAF outcomes where they apply.
You patch. We re-test every confirmed issue, for free, and issue a sign-off letter for customers and auditors.
United Kingdom
UK buyers do not want a Nessus PDF. They want evidence that stands up in a Cyber Essentials Plus review, an ISO 27001 Stage 2, a PCI ROC, or an enterprise security questionnaire.
Findings mapped to OWASP, ISO/IEC 27001 Annex A and NCSC CAF objectives. CVSS v3.1. Signed letter of attestation you can attach to procurement.
Calls during GMT/BST office hours. Same-day replies on working days. Quotes and invoices in pounds sterling. VAT treatment confirmed in the statement of work.
Every job starts with a signed authorisation letter covering the Computer Misuse Act 1990. NDA on request. Data deleted after close, report retained as agreed.
Most work is remote. When it helps we will sit with your engineers in London or another major UK city for scoping, a workshop, or a findings debrief.
Practice lead
VAPT.UK is led by Hassan Jawaid. Five-plus years of legal offensive work on bug bounty programmes, three-plus years delivering professional penetration tests. The same adversary mindset, now as a UK practice.
Over 1,000 real bugs reported to companies including Samsung, Binance, cPanel, F5, Ubisoft and SAP. Your engagement gets that attention — attacker paths, not a scanner dump.
Platform rankings
P1 Warrior Level 2 · Bounty Bee Level 7 · Submission Shogun Level 8 · MVP of October 2020 · Top Performer at Cubix, 2023 & 2024.
56+ security halls of fame — Samsung, Walmart, SAP, Atlassian, Deutsche Bank, Ubisoft, Binance and more.
Recognized by the best
Responsibly disclosed vulnerabilities, publicly acknowledged — Fortune 500s, banks, and government programmes. The same operator runs every VAPT.UK engagement.
FAQ
What UK teams usually ask before they book.
Notes
What boards, CISOs and founders in the UK actually need to know before they buy a pentest.
CE and CE+ are necessary. They are not an attacker simulation.
→ NCSC CAFCAF is an outcome framework. A pentest is one control.
→ UK GDPRArticle 32 is not a shopping list.
→