Scope
You tell us the estate and the driver — an audit, a customer requirement, a board question. We come back with scope, fee and dates in writing.
Loading...
Manual-led penetration testing and continuous compliance evidence for Malaysian teams that need findings they can fix — and proof an auditor can trust.
CURRENT ENGAGEMENT
Fintech API assessment
IDOR on /api/v2/statements — cross-tenant read
critical severity
JWT alg confusion → auth bypass
critical severity
Race condition in FPX payment callback
high severity
3
Open
11
Evidence
24h
Critical SLA
Offensive security
Every engagement combines manual testing, evidence, remediation guidance and an included retest.

Web, mobile, API, cloud, network and wireless — manual-led, PTES and OWASP WSTG methodology, CVSS-scored findings with proof of concept.

Full attack-path work: perimeter recon, lateral movement, social engineering and physical, scoped with rules of engagement.

Incident-driven review of what happened, with chain-of-custody handling for anything that may end up in front of a regulator.

Continuous external exposure monitoring plus recurring scanning with human verification, so the queue is real findings only.

Gap baselines and audit preparation for RMiT, ISO 27001, PDPA, PCI DSS, SOC 2 and Cyber Security Act readiness.

MDR and SOC-as-a-service with a 24/7 incident response hotline and threat intelligence including dark-web brand exposure.
nCrypt Radar
Findings, controls, evidence and audit access in one secure workspace — without spreadsheet archaeology.
Critical 24 hours, high 7 days, medium 30, low 90 — measured from the moment the finding lands, not from when someone reads the report.
Every artefact fingerprinted on upload so an auditor can prove what was collected and when.
Automated tests re-evaluate your controls daily; a failing test marks the control it maps to as non-compliant.
Read-only rooms for your auditor and your own customers, instead of emailing PDFs around.
CONTROL HEALTH
92% compliant
AWS
Google Workspace
Okta
GitHub
Jamf Pro
SentinelOne
Cloudflare
Jira
Slack
How engagement works
You tell us the estate and the driver — an audit, a customer requirement, a board question. We come back with scope, fee and dates in writing.
Manual-led testing against PTES, OWASP WSTG and NIST 800-115, with findings raised as they are confirmed rather than held to the end.
Findings arrive in the platform with reproduction steps and a fix owner, ordered by severity and SLA rather than by page number.
We verify the fixes at no extra charge, then package the evidence mapped to the framework your auditor or regulator asks about.
Hundreds
Engagements delivered
Across regulated sectors since 2020
OSCP
Certified consultants
Plus CEH; CREST-aligned methodology
2 hrs
Average response time
24/7 incident response hotline
GMT+8
Local delivery
MYR pricing, BM and EN reporting
Compliance mapping
Collect evidence once, map it to Malaysian and global requirements, and keep the audit trail live.
Mandatory for MY banks
Risk Management in Technology for licensed financial institutions, banks, DFIs and digital insurers.
7 mandatory principles
Personal Data Protection Act 2010 and the 2025 amendments, for data controllers and processors in Malaysia.
Akta 854
National Cyber Security Agency compliance for National Critical Information Infrastructure entities.
93 Annex A controls
Information Security Management System certification readiness with automated evidence collection.
Automated 24/7 checks
Trust Services Criteria — security, availability, confidentiality and privacy — for global enterprise deals.
6 control objectives
Payment Card Industry Data Security Standard for merchants and payment service providers in ASEAN.
Platform pricing
Start with one framework, then reuse the same controls and evidence as requirements grow.
One framework, continuous monitoring, and the trust room.
Multi-framework, annual pentest included, auditor access.
For regulated teams with their own auditors and SLAs.
Pentest scoping
Choose what needs testing. We will validate the assumptions, fee and dates with you in writing before work starts.
Typical for this shape: one window, findings raised as they're confirmed, retest 2 weeks after sign-off.
Send this scopeStraight answers
Tell us the estate and the deadline. An engineer will come back with scope, fee and dates — usually within two hours.