Application security
Manual testing of the software you build, from UI to source, per OWASP standards.
- Web, mobile & desktop apps
- Source code review
- AI & LLM security
We simulate real-world adversaries to expose what your defenses miss. A boutique firm where every engagement is led by a senior specialist.
Trusted security partner. Copenhagen, Denmark.
SERVICES
Grouped into three pillars. Every engagement is run hands-on by a senior specialist.
Manual testing of the software you build, from UI to source, per OWASP standards.
From cloud IAM to Active Directory: how far an attacker can actually get.
Security wired into your pipeline, your hardware, and the bugs scanners typically miss.
REPRESENTATIVE CASE STUDIES
Representative engagements showing how we work and what changes afterwards.
Security debt was building with every sprint. We embedded the controls to stop it without slowing delivery.
A Nordic energy operator needed clarity on post-breach exposure across critical infrastructure. We ran the simulation to find out.
US market entry required FDA pre-market security validation. We delivered the full assessment and source code audit to meet the submission requirements.
A Nordic bank on a DORA deadline needed technical validation across cloud and SWIFT infrastructure. We ran the audit to get it across the line.
INDUSTRIES
Compliance frameworks differ by sector. Engagements are scoped to the standard your regulator or customers actually require.
Premarket cybersecurity documentation and penetration testing of device software, companion apps, and connected platforms aligned to FDA guidance.
Threat-led penetration testing and resilience evidence mapped directly to DORA articles and PCI-DSS scope.
Annual pentests and CI/CD-integrated testing that produce the evidence your auditors and enterprise customers ask for.
Assessments of IT/OT boundaries, remote access paths, and control-adjacent systems for NIS2-covered operators.
Testing of embedded devices, production networks, and supplier integrations where downtime is not an option.
PRICING
Fixed prices agreed before work begins. No hidden fees, no retainer lock-in.
Fixed-scope test with a comprehensive report. The natural fit for annual compliance cycles: NIS2, DORA, ISO 27001, SOC 2.
Typically 5 days, from DKK 55,000 excl. VAT. Fixed price agreed before work begins.
A pre-purchased block of hours to draw down throughout the year. Security testing in your CI/CD sprint cycles with no procurement friction.
Day-rate DKK 11,000 excl. VAT. No retainer lock-in.
ENGAGEMENT LIFECYCLE
Six stages from first call to verified remediation. The verification test is always included.
Define target assets, constraints, and Rules of Engagement (RoE). Same specialist, start to finish.
Formalizing the engagement through a signed NDA and Statement of Work (SOW).
Active manual exploitation and vulnerability verification following OWASP/NIST/MITRE standards.
Executive risk summary and prioritized remediation roadmap.
Technical consultation with your engineering team to interpret findings and harden the perimeter.
Validation of applied patches is included in every scope at no extra cost to ensure all technical risks are neutralized.
ABOUT
One specialist owns your engagement from scoping to verification.
Founder & Technical Lead
Over 10 years in offensive security, built on a decade as a software engineer. That foundation shapes how engagements are scoped, what gets prioritised, and how findings land with the teams that have to fix them. Coverage spans web, mobile and desktop, cloud infrastructure, Active Directory, source code, endpoints, IoT and firmware, and AI/LLM systems.
Certifications
Get in touch
Tell us what you need tested. We'll get back to you within one business day. Or reach us directly at ssa@ssait.dk
"Our goal isn't just to hand over a PDF of vulnerabilities. We work as a technical partner to ensure your team understands the root cause and the path to remediation."
By submitting, you agree to our Privacy Policy.