cyberagent.id

Security audit

Security Audit for Applications and Infrastructure

An audit that serves two audiences: engineers who have to fix things, and management who has to understand the risk.

Introductory program

Free security audit

One full engagement at no fee, delivered to the same standard and depth as a paid one. In return we ask for one thing: recognition — permission to reference this engagement in the cyberagent.id portfolio. You may remain anonymous.

Request a scoping call Read the documentation

What the output is used for

Scope you can combine

Applications & APIs

Black-box and grey-box testing of customer-facing and internal web apps and APIs.

Source-code review

Authentication flows, input validation, secret storage and trust boundaries between systems.

Infrastructure & cloud

Internet-exposed services, TLS configuration, access policies and stored credentials.

AI systems

Resilience of chatbots and assistants to prompt injection and data leakage through model answers.

Reference standards

Testing follows PTES stages, the OWASP risk lists (Top 10, API Security Top 10 and the LLM guidance), CVSS 3.1 for impact scoring, and control mapping to ISO/IEC 27001 and NIST CSF. Standard names are working references — we are not a certification body.

Frequently asked questions

Can this audit be used for compliance?

The output works as internal compliance evidence and certification preparation: findings are mapped to ISO/IEC 27001 and NIST CSF control clusters. Certificates themselves are issued by accredited certification bodies.

How long does it take?

About two to seven working days for one application with a focused scope; two to four weeks when applications, source code, infrastructure and AI systems are all in scope.

How is this different from an automated scanner?

Scanners find common error patterns. People find the access control missing on one endpoint, business logic that can be bent, and password reset flows that allow account takeover. We use both and always include the manual evidence.

Can non-technical staff read the report?

Yes. Each finding carries a business-impact summary next to the technical detail, and the executive summary puts the main risks in management language.

Related services

Start with one email to founder@cyberagent.id listing the assets you want tested. You get scoping questions and a written quote back.