Skip to content
Genus

Penetration testing and VAPT

Find the weaknesses before an attacker does.

Genus tests your websites, applications and APIs for security weaknesses, with your written permission. You receive a clear report, proof for every finding and a recommended fix, followed by a retest once your team has made the changes.

How an engagement works: you approve the scope, covering your applications, APIs and login systems. We test it and deliver a findings report, a remediation plan and a retest.
  • Applications
  • APIs
  • Login & Access
  • Approved Scope
Genus
  • Findings Report
  • Remediation Plan
  • Retest

The challenge

A compliance certificate does not mean your systems are secure.

Customer records, payments and daily operations now run through web applications, portals and APIs. Automated tools have made it faster and cheaper to find and exploit weaknesses in these systems.

Many organisations complete an annual VAPT to meet audit or regulatory requirements. A basic scan can satisfy the audit while missing the weaknesses an attacker would actually use.

Our testing is designed to meet both needs.

Our approach

We test your systems the way an attacker would. Then we help your team fix what we find.

Every engagement begins with a written scope that you approve. Our engineers, supported by our AI-assisted testing platform, examine the systems in that scope, confirm each finding by hand and document how it can be exploited. We then work with your team until the fixes are verified in a retest.

Every engagement includes:

  • A written scope and rules of engagement, approved by you before testing begins

  • Proof of concept for every finding, with a severity rating

  • A detailed report with an executive summary, methodology and prioritised fixes

  • A scheduled retest after remediation, with verified results

  • A named point of contact from the team that carried out your test

Our commitments

Written authorisation. Confidential findings. Verified results.

We test only what you have authorised in writing. Your findings are shared only with your team and are never published. Any research we publish uses our own test systems or material cleared for release.

Research and publicationsComing soon

Common questions

Frequently Asked Questions

Answers on scope, safety and deliverables.

100%

Authorised scope

  • Proof for every finding
  • Retest included

Genus is an independent cybersecurity firm specialising in penetration testing. We test your applications and systems with your written permission and provide a report with proof and recommended fixes.

A penetration test is an authorised, controlled attempt to find and exploit weaknesses in your systems, so they can be fixed before they are misused.

Testing is planned around an agreed scope and schedule to minimise disruption. As no test is entirely without risk, we agree off-limits actions and an emergency contact before starting.

An initial discussion, a list of the domains or applications to be tested, and test credentials where required. We prepare the scope and the paperwork.

Yes. Testing is carried out only after the owner of the systems signs a permission-to-test document. Nothing outside the agreed scope is tested.

A standard VAPT often relies on automated scans, and an audit checks controls against a standard. We confirm each weakness by hand, show how it could be exploited and retest after your fixes.

You receive a report describing each finding, its business impact and a prioritised remediation plan. Your engineers can discuss the findings directly with ours, and we retest once fixes are in place.

Both options are available. The standard engagement includes the full report, proof and remediation plan. The extended engagement adds working sessions with your engineers and proposed patches.