Penetration Testing

Pentest & Red Team

Qualified auditors, some PASSI LPM accredited, use a methodical process to assess the vulnerabilities of your systems: applications, infrastructure, cloud environments, connected devices or the human factor. Each engagement builds realistic threat scenarios and estimates their likelihood, up to Red Team: a full attack simulation under real-world conditions.

Web Applications

Front-end, back-end and API analysis to detect application flaws (injection, access control, business logic...) exploitable by an external attacker.

Mobile Applications

Security assessment of iOS and Android applications: code analysis, local storage, network traffic and authentication mechanisms.

Infrastructure & Network

Simulated attacks against your servers, VPNs, firewalls and Active Directory to assess the robustness of your internal and external technical foundation.

Cloud Environments

Identification of configuration errors and infrastructure vulnerabilities across your AWS, Azure or GCP environments (IAM, storage, network, containers).

Connected Devices (IoT)

Audit of the hardware, firmware and communication protocols of your connected devices, from embedded electronics to associated applications.

Social Engineering

Testing your employees' vigilance through phishing scenarios, fraudulent calls or physical intrusion attempts into your premises.

Red Team

Full, stealthy attack simulation combining technical intrusion, social and physical engineering, to assess your overall detection and response capability.

  • PASSI LPM
  • Black Box
  • Grey Box
  • White Box
Our Method

A Four-Phase Approach

A standardized methodology, whatever the scope audited.

1. Scoping

Defining the scope, threat scenarios and engagement objectives together with your teams.

2. Identification

Searching for vulnerabilities by combining automated tools with in-depth manual analysis.

3. Exploitation

Controlled exploitation of identified flaws to validate their real impact on your system.

4. Reporting

Prioritized operational report, executive summary for your management and an immediately actionable plan.

Regulatory Compliance

Sector-Specific Audits

Audits tailored to the standards and regulations of your industry.

Ségur Audit

Verifies the compliance of your healthcare software solutions with the French Ségur du Numérique en Santé program, based on the PGSSI-S framework and interoperability requirements (Pro Santé Connect, DMP, MSSanté), leveraging HDS certification where needed.

  • PGSSI-S
  • Ségur du Numérique

Why: secures access to Ségur funding, guarantees interoperability with government services and strengthens the trust of your healthcare partners.

AMF Audit

Checks the compliance of your information system with the cybersecurity requirements of the French Autorité des Marchés Financiers (AMF), based on AMF recommendations, the European DORA regulation and the ISO 27001 standard, including for digital asset service providers (PSAN).

  • AMF
  • DORA
  • PSAN

Why: secures your authorization, demonstrates your operational resilience and reassures investors and partners.

ISO 27001 Audit

Verifies the compliance of your information security management system with the ISO/IEC 27001 standard, covering the Annex A controls and ISO/IEC 27002 best practices.

  • ISO 27001
  • ISO 27002

Why: demonstrates mature security governance, streamlines your tender responses and prepares you confidently for official certification.

SecNumCloud Audit

Verifies the compliance of your cloud service offerings with ANSSI's SecNumCloud framework: security governance, identity management, infrastructure security, encryption and data reversibility.

  • SecNumCloud
  • ANSSI

Why: opens access to public procurement and regulated sectors (healthcare, finance) and strengthens trust in your data sovereignty.

HDS Audit

Checks the compliance of your health data hosting infrastructure with the French HDS framework, based on the ISO 27001, ISO 20000-1 and ISO 27018 standards.

  • HDS
  • ISO 27001
  • ISO 20000-1
  • ISO 27018

Why: secures your right to host personal health data and reassures software vendors and client institutions.

FDA Audit

Validates the cybersecurity compliance of your connected medical devices with FDA requirements (Premarket/Postmarket Cybersecurity Guidance), based on the IEC 62304, IEC 81001-5-1 and AAMI TIR57 standards.

  • FDA
  • IEC 62304
  • AAMI TIR57

Why: includes producing an SBOM and secures access to the US market by demonstrating control of your cyber risks.

CRA Audit

Verifies the compliance of your digital products with the European Cyber Resilience Act (CRA), against Annex I of the CRA and the ETSI EN 303 645 and IEC 62443 standards.

  • CRA
  • ETSI EN 303 645
  • IEC 62443

Why: producing an SBOM and securing your entry to the European market by demonstrating regulatory compliance.

Expertise

Beyond the audit itself, our experts understand security challenges, identify issues specific to your context and determine the most suitable project strategy to guarantee its success, from scoping through to go-live.

Need an audit or support?

Let's discuss your regulatory context and the scope best suited to your needs.

Request a meeting