FD.Solutions

Security Testing & Assessment

01

Web Application Penetration Testing

Manual, in-depth testing of your live platform.

Automated scanners find known vulnerabilities in known software. They don't find broken authorization logic, business logic flaws, or the chain of three small issues that together become critical. That takes a human being who thinks like an attacker.

We test against the OWASP Web Security Testing Guide: authentication and session management, access control at object and function level, injection across all input paths, business logic abuse, file handling, and configuration.

  • Black-box, grey-box, or white-box engagements
  • Authenticated testing across every user role
  • Production or staging, scoped to your requirement
  • Full findings report with CVSS scoring, evidence, and reproduction steps
Scope this engagement
02

Mobile Application Security Testing

Android and iOS, tested against the OWASP MASTG.

Mobile apps carry risks web testing never surfaces — credentials cached in insecure storage, certificate validation that can be bypassed, secrets compiled into the binary, and backend APIs that trust the app far more than they should.

  • Static analysis of the APK, IPA, or source
  • Runtime and dynamic analysis on real devices
  • Local data storage and encryption review
  • Certificate pinning, root and jailbreak detection assessment
  • Testing of the backend APIs the app depends on
  • Play Store and App Store security requirement review
Scope this engagement
03

API & Backend Security Testing

Where the real damage happens.

Most modern breaches go through the API, not the interface. Broken object-level authorization — one user reaching another user's records by changing an ID — remains the most common critical finding in the field, and no automated tool reliably catches it.

  • Authentication and token handling review
  • Object-level and function-level authorization testing
  • Rate limiting and resource exhaustion
  • Input validation and injection across all endpoints
  • REST, GraphQL, and webhook security
Scope this engagement
04

Vulnerability Assessment & Scanning

Broad, systematic coverage of your whole estate.

Penetration testing goes deep on a defined scope. Vulnerability assessment goes wide — every internet-facing host, service, and open port, checked systematically and repeatedly.

  • External infrastructure scanning
  • Authenticated internal scanning
  • Configuration and hardening review
  • Remediation plan ranked by real exploitability, not raw CVSS
  • Quarterly or continuous scanning subscriptions
Scope this engagement
05

Network & Infrastructure Assessment

  • External and internal network testing
  • Cloud configuration review (AWS, Azure, DigitalOcean, and others)
  • Server and operating system hardening assessment
  • Firewall and network segmentation validation
  • Segmentation testing where PCI scope reduction is claimed
Scope this engagement

Code & Binary Analysis

06

Source Code Security Review

Reading the code finds what testing the interface can't.

A penetration test sees your application from the outside. A code review sees the logic — the authorization check that was never written, the query built by string concatenation, the secret committed to the repository two years ago and never rotated.

  • Manual review of security-critical paths: authentication, authorization, payment handling, data access
  • Automated static analysis (SAST) with manual triage to remove false positives
  • Dependency and supply-chain review — outdated and compromised packages are now among the most common real-world breach routes
  • Secret detection across the repository and its full history
  • Findings mapped to file and line, with fixed-code examples
  • Supported across Python, PHP, JavaScript/TypeScript, Java, Kotlin, and Go
Scope this engagement
07

Reverse Engineering & Binary Analysis

Understanding software from the inside out.

When there's no source code, analysis has to happen at the binary level. We decompile, disassemble, and analyze applications to establish what they actually do — as opposed to what the documentation claims.

  • Android APK decompilation and analysis
  • Extraction of hardcoded credentials, API keys, and endpoints
  • Obfuscation, anti-tampering, and anti-debugging assessment
  • Analysis of third-party software before you deploy it in your environment
  • Suspicious binary and malware analysis
  • Repackaging and tampering resistance testing

All reverse engineering work is performed on software you own or are contractually authorized to analyze. We require written authorization before any engagement begins.

Scope this engagement

Hardening & Implementation

08

Server & Cloud Hardening

Findings turned into a fixed environment.

An assessment tells you what's wrong. Hardening makes it right — and keeps it right, because the boring work of patching, certificate renewal, and backup verification is exactly what gets forgotten.

  • Operating system hardening for Linux and Windows Server
  • SSH, firewall, and remote access lockdown
  • TLS configuration, security headers, and Content Security Policy
  • Cloud IAM review and least-privilege enforcement
  • WAF, DDoS protection, and rate limiting
  • Container and Docker security configuration
  • Centralized logging, monitoring, and alerting
  • Automated encrypted backups with tested restores
  • Hardening benchmarked against CIS Controls
Scope this engagement
09

Secure Development

Systems built to pass the assessment, not scramble before it.

We build web platforms and applications with security designed in from the architecture stage — minimal attack surface, proven frameworks, and infrastructure hardened before launch rather than after the first report comes back.

  • Web platforms and customer portals built on Django and PostgreSQL
  • Backend and API development with authorization enforced at the object level
  • Static sites where no server-side code needs to exist at all
  • Payment integration architected to keep card data off your servers entirely
  • Full Arabic and RTL support
  • Secure deployment, monitoring, and handover — you own the code and the accounts
Scope this engagement

Compliance & Documentation

10

Security Policies & Compliance Documentation

The paperwork auditors and banks actually ask for.

Most organizations fail their first review not because their security is bad, but because nothing is written down. Auditors assess what's documented; if it isn't on paper, it doesn't count.

  • Information security policy and supporting procedures
  • Incident response plan and escalation procedures
  • Business continuity and disaster recovery plans
  • Access control, password, and acceptable use policies
  • Data protection and privacy policies, retention and deletion schedules
  • Risk assessment and risk register
  • Data flow diagrams and asset inventories
  • Vendor and third-party risk management procedures
  • Bilingual delivery in Arabic and English

Prepared for PCI DSS, ISO 27001 readiness, and bank or PSP onboarding requirements.

Scope this engagement
11

Compliance & Bank Onboarding Reports

Documentation built for the specific reviewer who will read it.

A bank onboarding a merchant, a QSA validating PCI scope, and an enterprise procurement team all ask for “a security report” and all mean something different. We produce the version that matches the requirement.

  • Penetration test reports formatted for bank and PSP merchant onboarding
  • PCI DSS scoped testing, including segmentation validation
  • Executive attestation letters stating scope, dates, methodology, and outcome
  • Complete supporting document packages
  • Guidance on which validation tier applies to your architecture — and how to reduce it
  • Support responding to enterprise client security questionnaires
Scope this engagement
12

Remediation Support & Retesting

A report with open findings doesn't get you approved.

Bank requirements aren't satisfied by a report listing vulnerabilities. They're satisfied by a report showing the vulnerabilities are gone.

  • Developer-facing remediation guidance specific to your stack
  • Direct technical support for your engineering team during fixes
  • Full retest and verification of every closed finding
  • Clean retest report confirming no outstanding high or medium severity issues
  • Retest included as standard within ⟨30⟩ days of the initial report
Scope this engagement

Training & Awareness

13

Security Training

Your people are the control that fails most often.

Most successful attacks don't defeat technology. They convince someone to hand over a password or approve a payment. Training is the cheapest security investment available and consistently the most neglected.

For all staff

  • Phishing recognition and reporting
  • Password practice and MFA
  • Social engineering awareness
  • Safe handling of customer and payment data
  • Incident reporting: what to do in the first ten minutes

For developers

  • Secure coding practice and the OWASP Top 10
  • Framework-specific security patterns
  • Code review with a security lens
  • Dependency and supply-chain hygiene

Delivery

  • On-site or remote workshops
  • Simulated phishing campaigns with reporting
  • Annual refresher programmes for compliance requirements
  • Arabic and English delivery
  • Completion records and certificates for audit evidence
Scope this engagement
14

Continuous Security Monitoring

Because a clean report has a shelf life.

Your platform changes. Dependencies age. New vulnerabilities are published weekly. An assessment is a snapshot, and by itself it goes stale.

  • Scheduled recurring scans, quarterly or monthly
  • Attack surface monitoring for newly exposed services
  • Alerting on newly published vulnerabilities affecting your stack
  • Annual retesting to maintain compliance
  • Ongoing advisory access for your team
Scope this engagement

What you receive

Every assessment delivers a complete evidence package, not a scanner export with a logo on it.

  1. Executive summary

    Overall risk posture in plain language for the person signing off, with an explicit statement of outstanding findings by severity.

  2. Technical findings report

    Each finding with CVSS v3.1 score, business impact, affected components, proof-of-concept evidence, and reproduction steps.

  3. Remediation plan

    Specific, actionable guidance ranked by priority, written for the developers implementing it.

  4. Scope and methodology statement

    Every tested URL, IP, endpoint, and application build with version numbers; testing dates; standards followed; tools used.

  5. Tester credentials and independence statement

    Certifications held and a signed declaration of independence. Compliance reviewers check this first.

  6. Retest report

    Verification that each finding is closed, with a clear final position.

  7. Signed and stamped attestation letter

    On company letterhead, in the format banks and PSPs expect.

Reports delivered in English and Arabic on request.

Find out what's exposed — before someone else does.

Tell us what you need tested and who's asking for the report. A short scoping call is usually enough to give you a clear scope, timeline, and fixed price.

Request a Scoping Call