Security audit
Security Audit for Applications and Infrastructure
An audit that serves two audiences: engineers who have to fix things, and management who has to understand the risk.
Introductory program
Free security audit
One full engagement at no fee, delivered to the same standard and depth as a paid one. In return we ask for one thing: recognition — permission to reference this engagement in the cyberagent.id portfolio. You may remain anonymous.
What the output is used for
- Internal compliance evidence: which controls work and which do not.
- Budget decisions: what to fix first, with an estimate of the impact.
- Answering security questions from corporate clients or partners.
- Preparation towards certification such as ISO/IEC 27001 — findings mapped to control clusters, without claiming to be a certification body.
Scope you can combine
Applications & APIs
Black-box and grey-box testing of customer-facing and internal web apps and APIs.
Source-code review
Authentication flows, input validation, secret storage and trust boundaries between systems.
Infrastructure & cloud
Internet-exposed services, TLS configuration, access policies and stored credentials.
AI systems
Resilience of chatbots and assistants to prompt injection and data leakage through model answers.
Reference standards
Testing follows PTES stages, the OWASP risk lists (Top 10, API Security Top 10 and the LLM guidance), CVSS 3.1 for impact scoring, and control mapping to ISO/IEC 27001 and NIST CSF. Standard names are working references — we are not a certification body.
Frequently asked questions
Can this audit be used for compliance?
The output works as internal compliance evidence and certification preparation: findings are mapped to ISO/IEC 27001 and NIST CSF control clusters. Certificates themselves are issued by accredited certification bodies.
How long does it take?
About two to seven working days for one application with a focused scope; two to four weeks when applications, source code, infrastructure and AI systems are all in scope.
How is this different from an automated scanner?
Scanners find common error patterns. People find the access control missing on one endpoint, business logic that can be bent, and password reset flows that allow account takeover. We use both and always include the manual evidence.
Can non-technical staff read the report?
Yes. Each finding carries a business-impact summary next to the technical detail, and the executive summary puts the main risks in management language.
Related services
Start with one email to founder@cyberagent.id listing the assets you want tested. You get scoping questions and a written quote back.