Exposure
Which assets, interfaces and trust boundaries are actually reachable inside the agreed scope?
VAPT Services
Maline provides authorised VAPT and penetration testing for web applications, APIs, mobile apps, cloud and exposed infrastructure, with findings written for the teams that have to fix them.
What the assessment should answer
Which assets, interfaces and trust boundaries are actually reachable inside the agreed scope?
Which weaknesses can be validated through controlled testing, and what conditions make them matter?
What should engineering or infrastructure teams fix first based on impact, evidence and business context?
Assessment scope
Testing starts with written authorisation, a clear scope and rules of engagement. The method changes with the system instead of forcing every assessment through the same checklist.
Authentication, session, access control, input handling, business logic and configuration within the agreed application scope.
Authorisation, authentication, resource consumption, business flows, inventory and unsafe integrations across exposed API surfaces.
Client-side storage, communications, authentication, platform configuration, backend/API interaction and privacy controls.
Internet-exposed services, configuration, identity, network boundaries and selected cloud controls where they are explicitly authorised.
Confirm ownership, targets, exclusions, test windows, data handling and escalation before testing begins.
Use controlled manual and tool-assisted techniques to verify meaningful weaknesses rather than reporting every scanner signal as equal.
Provide evidence, impact, reproduction context and remediation guidance, then verify agreed fixes when retesting is included.
Need an independent view before launch or after remediation?