PENETRATION TESTING

Penetration testing services

Hire an ethical hacker who tests your systems by hand, the way a real attacker would.

I'm Marco Candeo, an independent security researcher and penetration tester. I've found more than 100 vulnerabilities across public bug bounty programs and private engagements, and I sit in the top 12 of HackerOne's Brazil leaderboard. When you hire me, I'm the one testing your application, from the scoping call to the final debrief.

Book a pentestSee what I've found

What I test

Most engagements cover one or two of these. We agree the scope before anything starts, and I don't touch what falls outside it.

Web application penetration testing

Authenticated and unauthenticated testing across each user role you have: broken access control, injection, authentication and session handling, and the business-logic flaws scanners miss. Most of my highest-severity findings come from chaining a small logic gap with an endpoint your team forgot was there.

API & backend security assessment

REST, GraphQL, and WebSocket APIs, tested against the calls your client makes and the ones it doesn't. IDORs, missing authorization checks, mass assignment, and injection paths that the front end filters but the API accepts.

Cloud & infrastructure review

Configuration review of the cloud accounts and services exposed around your application: over-permissive IAM, public storage and admin interfaces, wider network exposure than you need, and secrets I can read from outside.

Mobile application testing

I reverse-engineer your Android and iOS builds to find hardcoded credentials, deprecated endpoints still live in production, weak certificate pinning, and sensitive data sitting in local storage.

How an engagement works

  1. 01

    Scoping call

    We go through what you've built, what worries you, and what falls in and out of scope. You leave with a fixed price and a date range, not an hourly estimate that drifts.

  2. 02

    Manual testing

    I spend weeks working through the application by hand. Automated tooling handles recon and coverage, not the testing itself.

  3. 03

    Report

    You get every finding with a severity rating, reproduction steps, evidence, and a concrete fix. I write it so your engineers can act on it and so you can hand it to a customer asking how you test.

  4. 04

    Retest

    Once your team ships the fixes, I verify each one and update the report. That retest is part of the engagement, not a separate invoice.

Why hire an independent tester

You talk to the person doing the work

I run the scoping call, I test your app, and I run the debrief. No junior tester takes over once you sign.

Three engagements a quarter

I cap the client count on purpose. That cap is what buys each client weeks of manual testing instead of a three-day sweep.

I read code the way your engineers do

I was a software engineer before I did this full time. I read your code the way your team wrote it, which is how I find the flaws that come from how you built the system.

No scanner reports

If a tool could have found it alone, I'm not billing you for it. You get findings that took someone sitting down and thinking about your application.

Frequently asked questions

How much does a penetration test cost?

It depends on scope: the size of the application, how many user roles and integrations it has, and whether you want mobile or infrastructure covered. After the scoping call you get a fixed price for the whole engagement, retest included.

How long does a penetration test take?

Most engagements run two to four weeks of testing plus reporting. I'd rather turn work down than compress a test into a few days. The findings that matter are not the ones you reach in the first afternoon.

What do I get at the end?

A written report with every finding, its severity, reproduction steps, evidence, and a remediation recommendation, plus a debrief call with whoever needs to be on it. After your team ships fixes, I retest and update the report.

Can you sign an NDA?

Yes. Anything under NDA stays out of my writeups, my videos, and this site. Everything here comes from public bug bounty programs that cleared me to talk after the patch shipped.

Do you test production systems?

Yes, in most cases, with rate limits and a testing window we both sign off on. If your staging environment mirrors production I'll use it, but the interesting bugs live in the real data flows, and staging doesn't carry them.

Will the report satisfy a customer security review?

I write it for a third-party reader: scope, methodology, findings, and retest results are all in it, which covers what most enterprise security questionnaires ask for. I'm not an accredited audit firm, so a formal certification audit still needs a certified assessor. An independent pentest report sits alongside that rather than replacing it.

Do you work with companies outside Brazil?

Yes. I work remotely, in English or Portuguese. Most of the programs I hunt on belong to companies outside Brazil.

Tell me what you need tested

Send a rough scope and a timeline. I answer my own email. Expect a reply inside two days.

Start a conversation