SECURITY AUDIT · PENETRATION TESTING

Security audits and AI engineering, with evidence you can verify.

We test your applications, APIs, servers and AI systems to find the holes before an attacker does — then hand you a report with proof, risk level, and the fix for each issue. We also build custom AI systems for daily operations, including deployments that stay on your own servers.

Services

2 service lines

Security audit and AI engineering on your own infrastructure.

Introductory program

Free audit

Delivered to the same standard as a paid engagement. In return: recognition — permission to reference the work in our portfolio.

Response

45 minutes

Email replies during Western Indonesian business hours (WIB, UTC+7).

SERVICES

Website, API and AI security auditing

Audits follow standards used across the industry, so results can be compared between reviews and reused as internal compliance evidence. For AI work we map the requirements first, test on real data, then move to production with access control and human escalation.

Second service line

Custom AI Engineering: customer-service assistants, sales and lead handling, voice and chat agents, an internal assistant that answers from your own documents, back-office automation, and AI models that run on your own infrastructure.

See AI Engineering →
Web & API
Security Audit

01 // AUDIT

Web & API Security Audit

We test login flows, permissions, input handling, business logic, sessions and third-party integrations — without damaging your data. Findings are mapped to the OWASP Top 10, the industry list of the ten most common web security risks.

Source Code
Review

02 // AUDIT

Source Code Review

We read the code you hand over line by line: how login works, how input is validated, where secrets are stored, and where one system trusts another too much. Every finding points to the exact file and line.

Server & Cloud
Audit

03 // AUDIT

Server & Cloud Audit

We map what is exposed to the internet — open services, TLS certificates, response headers, undocumented entry points — then review access policies, stored credentials and the misconfigurations that keep coming back.

AI System
Audit

04 // AUDIT

AI System Audit

If you use a chatbot or any AI feature, we check whether it can be talked into breaking its own rules, leaking internal data, or reaching information it should not see. This is the OWASP guidance for AI systems, applied to your actual deployment.

HOW WE WORK

Every finding is proven, not just claimed

cyberagent.id is a security audit and AI engineering firm. We test systems up to their limits and build AI that is actually used in production, not demos. Reports are written so your engineers can act on them and your management can understand the risk.

Two rules apply to every engagement: each finding comes with the steps to reproduce it, and we are honest about limits — including what we did not test. Anything we cannot reproduce does not go into the report.

DEPLOYMENT

Your data stays on your infrastructure

For AI work, systems can run on your own side: in-country cloud, your office servers, or with no internet connection at all. Customer data, transcripts and documents are never used to train third-party models.

01 // OPTION

In-country cloud

Runs on infrastructure inside your jurisdiction, with no copy of the data sent to other regions.

02 // OPTION

Your own servers

Installed in your data centre and reached by your internal systems over your internal network.

03 // OPTION

Fully offline

No outbound internet connection at all, for environments where that is a legal requirement.

04 // OPTION

Fixed scope, your code

Work runs as a fixed-scope project or a retainer, and the code and configuration we build are yours.

STANDARDS

Mapped to standards the industry already recognises

Every audit is mapped to international standards, so results can be compared between reviews and reused as internal compliance evidence.

01 // STANDARD

OWASP Top 10

The industry list of the ten most common web application risks — weak login, broken access control, injection, and similar — used as the baseline for every web and API audit.

02 // STANDARD

AI system testing guidance

OWASP reference for AI systems: prompt injection, data leaking through AI answers, and agents abusing the tools they are given.

03 // STANDARD

MITRE ATT&CK & NIST CSF

A map of how attackers actually operate, placed inside an organisation-level risk framework your management already understands.

04 // STANDARD

PTES, ISO 27001 & CVSS

Testing phases, the link back to ISO information-security controls, and CVSS — the standard score that says how severe a finding is.

COMMON QUESTIONS

Questions buyers ask before the first call

Short answers to the things people search for before they hire anyone for security testing or AI work.

What is a security audit, and why does my business need one?

A security audit is a structured attempt to break into your own application, API or server — with your permission — so you learn about the holes before an attacker does. If you store customer data, take payments or run logins, the audit tells you exactly what is exposed today and what to fix first.

How much does a penetration test cost?

Price follows scope: how many applications are involved, whether source-code review is included, and how deep the testing goes. You get a fixed per-project quote after a short scoping call — no open-ended retainer, and the number is agreed before any work starts.

What does a web application and API security audit include?

Web application testing against the OWASP Top 10, API testing against the OWASP API Security Top 10, source-code review, external infrastructure and cloud configuration review, and AI system review. Every finding includes reproduction steps, a CVSS 3.1 score and a concrete remediation.

Do you need production access or real customer data?

No. Testing runs against a staging copy wherever one exists. If production is the only option we restrict ourselves to non-destructive checks, and we never exfiltrate real customer data.

How long does an assessment take?

From about two days for a single small application up to four weeks for an engagement covering several systems. The report is handed over after a debrief walkthrough with your engineers, so the fixes are clear to the people who implement them.

Can chatbots and AI systems be security tested too?

Yes. If you run a chatbot, an AI agent or an LLM feature, we test whether it can be pushed outside its instructions (prompt injection), leak internal data through its answers, or reach tools and data it should not. We also build and operate those systems, including private deployments that run on your own servers.

GET STARTED

Start with one email

Send a short brief: what you are protecting, which systems are involved, and what you expect to get out of it. You receive scoping questions, then a proposal with scope, timeline and price. No long procurement process — one email, one 30-minute call, one proposal.

Request a Scoping Call

Replies within 45 minutes during Indonesian business hours (WIB). The dashboard and public API are still in development — every service is currently handled by email.