Comprehensive Security Assessment and Penetration Testing
Although an automated scanner can expose certain vulnerabilities, there is no substitute for a comprehensive assessment of your product’s security by a group of Class-A experts engaged closely with your team.
For the most effective use of time, we recommend a source-assisted pen-test. White box and black box approaches both have their merits, but by combining the two into a “gray box” approach, we leverage information from the code to improve testing and pinpoint critical pieces of the code for thorough review. This method saves time while identifying the highest number of design and code-level bugs.
Casaba can engage in vulnerability research for you through fuzzing, XSS testing, and security testing application logic, inputs, outputs, communications and more.
Casaba has deep experience reviewing the security of complex systems and providing guidance to plan for and protect against the latest attacks and threats. We're flexible enough to work through the early stages of a v1 product, or join in the later stage development of a more mature product.
We will gladly provide references that will confirm our expertise in these and other areas:
- Mobile platforms
- Embedded systems and IC
- Cloud-based services
- Online games
- Top-tier social networking sites
- Top-tier instant messaging products
- Web applications
- Cryptographic designs and implementations including content-level DRM and network-level (e.g. IPSec)
- Peer-to-Peer applications
- Operating system components and applications


