Start a build Book an assessment
Services
Penetration Testing Web App Pentest API Pentest LLM & AI Pentest Cloud & Infra Security Compliance Readiness Secure Code Review Web App Development Software Development
Work Trust Insights Company Contact Start a build Book an assessment

Find the breach before attackers do.

RASTTSec is a cybersecurity and software development partner. We test your web, API, cloud and LLM systems the way a real adversary would — and then we build the software that closes what we find, from customer-facing web applications to the internal platforms behind them.

Methodology aligned to the standards your auditors already read

OWASP Top 10 OWASP API Top 10 OWASP LLM Top 10 PTES MITRE ATT&CK NIST SP 800-115 CVSS v4.0 ISO 27001 alignment SOC 2 readiness PCI DSS v4.0 OWASP Top 10 OWASP API Top 10 OWASP LLM Top 10 PTES MITRE ATT&CK NIST SP 800-115 CVSS v4.0 ISO 27001 alignment SOC 2 readiness PCI DSS v4.0
Who we are

Security testers and software engineers, under one roof.

RASTTSec exists because the gap between a penetration test report and a working fix is where most security programmes quietly fail. Our testers hand findings to engineers who sit in the same stand-ups, so remediation is realistic, prioritised and — if you want it — delivered rather than described.

  • Senior-only delivery: the consultant who scopes the engagement is the one testing it.
  • Aligned to recognised standards — OWASP, PTES, NIST SP 800-115, CVSS v4.0.
  • Evidence over opinion: if we cannot reproduce it, we do not report it as confirmed.
  • Discretion as standard: NDA before scoping, minimum necessary access, agreed deletion timelines.
How we are set up
Remote-first deliveryEngagements run worldwide, subject to sanctions and export-control checks
On-site where it mattersInternal network and physical-adjacent scopes are delivered in person
Business hoursSunday–Thursday 09:00–18:00 (Asia/Dhaka); testing windows can run outside them
Two practices, one teamOffensive security and product engineering, working from the same backlog
Our services

Nine service lines. One team that breaks things and one that builds.

Attack surface first, then the engineering to close it. Most clients start with an assessment and grow into a retainer or a build.

Industries

Where the same findings keep appearing.

Sector context changes what matters. A test on a fintech ledger and a test on a hospital portal look nothing alike, even when the underlying flaw is the same class.

Fintech & paymentsTenant isolation, ledger integrity, API authorisation, PCI scope
HealthcarePatient-data exposure, third-party integrations, cloud drift
E-commerce & retailCheckout logic, pricing trust, bot and fraud abuse
SaaS & platformsMulti-tenancy, SSO, GraphQL, customer-facing AI features
Government & public sectorCitizen data, supplier risk, audit-ready evidence
Logistics & marketplacesPartner APIs, tracking data, operational uptime
Why teams pick RASTTSec

Not another scanner with a PDF template.

Every engagement is run by senior testers who exploit the finding, capture the evidence, and write the reproduction steps your engineers need. No raw tool dumps, no severity inflation.

  • Senior-only delivery: the person on the call is the person testing.
  • Proof-over-theory: findings reproduced end to end with evidence retained for retest.
  • Fix-side help included — remediation guidance and developer walkthroughs.
  • Rules of engagement signed before a single packet moves.

Fast to a real finding

Kickoff within days of scope sign-off. Critical issues are escalated the moment they are confirmed — you do not wait for the report.

Two reports, one truth

An executive brief your board can read and a technical report with CVSS v4 vectors, payloads and step-by-step reproduction.

Confidentiality by default

NDA-first, minimum data handling, encrypted evidence storage and destruction timelines agreed up front.

Builders on the same bench

Our engineers ship software too, so remediation advice is written by people who have to live with the fix.

How an engagement runs

Six phases, no surprises.

01

Scoping & rules of engagement

Targets, exclusions, testing windows, emergency contacts and legal authorisation are agreed in writing before testing starts.

02

Reconnaissance

Passive and active discovery of assets, endpoints, identities and third-party dependencies to define the real attack surface.

03

Exploitation

Manual testing targeted at the flaws automation cannot reason about: authorisation logic, chained trust boundaries, prompt injection, privilege escalation.

04

Validation & impact

Every candidate finding is reproduced and scored with CVSS v4. What cannot be reproduced is not reported as a confirmed issue.

05

Reporting & walkthrough

Executive summary, technical detail, remediation guidance and a live session with your engineers to answer questions.

06

Retest & closure

A retest window confirms what was fixed, what regressed, and what still needs attention — evidence retained for your auditors.

0
Engagements delivered
0
Service lines covered
0
Findings reproduced before reporting
0
Typical report turnaround

NDA first

We sign before scoping detail is shared — yours or ours, whichever your legal team prefers.

DPA & questionnaires

Data processing addendum and vendor security questionnaires completed by a named contact, not a template bot.

Fixed scope, fixed price

Written scope, deliverables, timeline and price before you commit. Change requests are agreed in writing.

Reference calls

Speak to an existing client in your sector on request — including one where the finding was uncomfortable.

Our work

What testing actually turns up.

Sanitised case studies from engagements across fintech, healthcare, e-commerce and SaaS.

FintechAPI

Cross-tenant invoice exposure in a payments platform

A single missing object-level authorisation check let any authenticated tenant read another tenant's invoices. Reproduced with two test accounts.

CriticalIDORAuthZ
3Critical
7High
9dTo fix
SaaSLLM

System prompt and data leakage in a support assistant

Role-play chains and indirect injection through retrieved documents exposed the system prompt and unrelated customer records.

HighPrompt injectionRAG
1Critical
6High
12dTo fix
HealthcareCloud

Public storage bucket behind a private patient portal

An IaC drift left a backup bucket world-readable while the application itself was solid — a reminder that the perimeter is not the app.

CriticalCloud configIaC drift
2Critical
4High
3dTo fix
What clients say

Trusted with the systems that cannot go down.

Sample content for preview — replace with approved client quotes and attribution.

FAQ

Questions we get before the kickoff call.

Still unsure what you need? Send us the architecture and we will tell you what is worth testing first.

Most web application or API engagements run one to three weeks of testing time depending on scope and complexity. We give you a fixed window and a report date at kickoff, and escalate critical findings immediately rather than holding them for the final report.
Staging first wherever the environment is faithful to production. Where business logic or infrastructure only exists in production, we test there under agreed windows, rate limits and a signed rules-of-engagement document.
Traditional application testing does not cover probabilistic behaviour. We test prompt injection (direct and indirect), jailbreaks, system-prompt disclosure, insecure tool and function calling, retrieval poisoning, and data exfiltration through model output.
Yes. We run a development practice alongside the security practice, so remediation can be handled by the same team that found the issue — or handed to your engineers with guidance and a free retest window.
NDA before scoping, minimum necessary data handling, encrypted storage for evidence, named access lists, and an agreed destruction timeline after the engagement closes. Details are published in our trust centre.
A written authorisation from someone entitled to grant it, a scope list, test credentials at the right privilege levels, and one technical contact reachable during the window. We provide the templates.
Start here

Let's find out what an attacker already sees.

Tell us what you are building or running. We will come back with a scoped plan, a fixed price and a testing window — usually within one business day.