PaladinX

Security-first software & web engineering

Cybersecurity and software that protect and power your business.

Penetration testing, a 24/7 security operations centre, and custom software — engineered by the people who break systems for a living.

4-hour reply

On working days

NDA first

Signed before scoping

No obligation

Assessment is free

Findings summary ENGAGEMENT 4417 · GREY-BOX · WEB + API
SEVFINDINGCVSS
CRIT
Authentication bypass on customer portal
POST /api/v2/session · CLOSED D2
9.1
CRIT
Unrestricted file upload leading to RCE
POST /documents/upload · CLOSED D4
8.8
HIGH
Broken object-level authorisation
GET /api/v2/accounts/{id} · CLOSED D9
7.7
HIGH
Privilege escalation via unconstrained delegation
directory / dc-02 · CLOSED D12
7.2
MED
Session token still valid after logout
auth-service · CLOSED D15
5.4
17
FINDINGS
4
CRITICAL
21d
TO CLEAN RETEST
ISO 27001–aligned
OSCP-led testing
24/7 SOC monitoring
Clients across four continents

§01 — WHAT WE DO

Three service lines. One security standard across all of them.

All services →
01

Security

Penetration testing, red-team and SOC simulation, monitoring and security-awareness training. We find what an attacker would find, then stay until it is closed.

Explore security →
02

Software

Custom applications and ERP systems, threat-modelled before a line is written: role-based access, audit trails, and a security test before release — not after.

Explore software →
03

Web

Websites and web platforms that are fast, accessible and hardened — clean code instead of untrusted plugins, and a hosting setup you can actually audit.

Explore web →

§02 — WHY PALADINX

Most suppliers bolt security on at the end. We start there.

PaladinX is led by offensive-security specialists and backed by an established technology group. The same team that is paid to break into banks and telecom networks reviews every application and website we ship. Nothing leaves here untested.

Read our story →
01

Led by offensive security

Every engagement is run and reviewed by people whose day job is breaking into production systems.

02

A company, not a freelancer

We are the security arm of a larger technology group — with the continuity, contracts and accountability that implies.

03

A SOC that does not sleep

Round-the-clock monitoring, detection and response — plus SOC simulation exercises that prove your own team is ready.

04

Documented, not improvised

ISO 27001–aligned processes, signed NDAs and evidence-backed reporting your auditor and your engineers can both use.

§03 — PROOF

Trusted where the stakes are highest.

CLIENT LOGO
CLIENT LOGO
CLIENT LOGO
CLIENT LOGO
CLIENT LOGO

“They found in four days what two previous audits missed — then stayed with our team until every finding was closed.”

Chief Technology Officer, international bank
Client name withheld under NDA
8
YEARS OPERATING
120+
PROJECTS DELIVERED
40+
CLIENTS SERVED
24/7
SOC COVERAGE

§04 — AFTER YOU BOOK

No sales funnel. Three steps, then real work.

1

A 30-minute call

We ask what you run, what worries you, and what you must comply with. No slides.

2

A scoped proposal in 48 hours

Fixed scope, fixed price, clear rules of engagement — signed before anything is touched.

3

Findings as we go

Criticals are reported the day we find them, not in a PDF six weeks later. Free retest after you fix.

FREE DOWNLOAD

The 12-point checklist we run before every engagement.

The controls we check first on every new client — exposure, identity, backups, logging. Two pages, no gate beyond your email.

One email with the PDF. No list, no follow-up sequence.

SERVICES

Test it. Build it. Ship it — with security in the foundations.

Three lines of work, one standard. Every engagement is scoped in writing, run under NDA, and reported with evidence you can hand to an auditor.

01

Security

Offensive security is our core discipline. We test the way a real attacker would — then translate what we found into fixes your engineers can action this sprint, and a summary your board can read in five minutes.

WEB & API INTERNAL NETWORK MOBILE CLOUD PHISHING SIMULATION SOC SIMULATION
Scope a security test →

What you get

/A written scope and rules of engagement, signed before we start
/Manual testing by certified testers — not just an automated scan
/Critical findings reported the same day they are found
/A full report: technical detail, evidence, CVSS ratings and a board summary
/A remediation workshop with your engineers
/A free retest once the fixes are in, plus a clean-status letter
/Security-awareness training and phishing simulation for your staff
02

Software

Custom applications and ERP systems for operations that spreadsheets have outgrown. We model the threats before we model the database — so access control, audit trails and data handling are design decisions, not patches.

ERP INTERNAL TOOLS INTEGRATIONS MOBILE APPS
Discuss a build →

What you get

/A discovery phase with process mapping and a written functional scope
/A threat model and data-flow diagram before development starts
/Role-based access control and a complete audit trail as standard
/Fortnightly demos — you see working software, not status reports
/A penetration test of the finished product, included in the price
/Source code, documentation and handover training — you own all of it
/A support and patching agreement after go-live
03

Web

Corporate sites and web platforms that load fast, rank well and survive scrutiny. Most sites we are asked to fix were broken by abandoned plugins and unpatched hosting — we build so that cannot happen.

CORPORATE SITES PORTALS E-COMMERCE MULTILINGUAL / RTL
Start a web project →

What you get

/Design and build, mobile-first, with an accessibility pass to WCAG AA
/A content editor your marketing team can use without us
/Hardened hosting: TLS, security headers, WAF, backups, monitoring
/Core Web Vitals in the green on a mid-range phone, not just on fibre
/Multilingual and right-to-left support built into the structure
/Analytics, search-console setup and a launch-day checklist
/A managed care plan: patches, uptime monitoring and monthly reporting

Not sure which one you need?

Most engagements start with a free assessment: we look at what is exposed, tell you what we would prioritise, and you decide what happens next.

Book a free assessment →

SELECTED WORK

Three engagements. Names withheld, results not.

Our clients operate in regulated and sensitive sectors, so we do not publish who they are. Everything below is real work, anonymised — full references are available under NDA on request.

CASE 01FINANCIAL SERVICES · PENETRATION TEST · 3 WEEKS

Pre-audit assurance for a new digital banking channel

Challenge

A new customer portal and mobile API were weeks from launch, with a regulator sign-off deadline and no independent security review. Two internal reviews had found nothing.

What we did

A grey-box test of the web app, API and mobile client; a phishing simulation against 340 staff; and a SOC simulation to measure how fast the in-house team detected us.

Result

17 findings, 4 critical — including an authentication bypass — all closed in three weeks. The retest came back clean and the channel launched on schedule.

4
CRITICAL FINDINGS
21d
TO CLEAN RETEST
31→6%
PHISHING CLICK RATE
On time
REGULATOR SIGN-OFF
CASE 02ENERGY LOGISTICS · CUSTOM ERP · 7 MONTHS

A fleet of 200 trucks, run on spreadsheets

Challenge

Dispatch, fuel reconciliation and customer billing lived in shared spreadsheets. No audit trail, no access control, and a failed vendor security review blocking a major contract.

What we did

Mapped the real process with dispatchers, then built a custom ERP: dispatch, fleet, fuel and invoicing, with role-based access, full audit logging and an offline-capable driver app.

Result

Dispatch time down 60%, month-end close from nine days to two, and the client passed their customer's vendor security review at the first attempt.

−60%
DISPATCH TIME
9→2
DAYS TO MONTH-END CLOSE
200
VEHICLES TRACKED
First pass
VENDOR SECURITY REVIEW
CASE 03INDUSTRIAL GROUP · CORPORATE WEBSITE · 6 WEEKS

A flagship site that had become the group's biggest liability

Challenge

An eleven-year-old site on an unmaintained CMS: three known critical vulnerabilities, nine-second load times on mobile, and no way for marketing to publish without a developer.

What we did

Rebuilt it static-first with a headless editor, migrated 240 pages, added security headers and a WAF, and ran a penetration test before launch rather than after.

Result

Largest contentful paint of 1.2 seconds, zero outstanding vulnerabilities, and roughly three times the enquiries within a quarter.

9s→1.2s
LARGEST PAINT
0
OPEN VULNERABILITIES
ENQUIRIES PER MONTH
240
PAGES MIGRATED

ABOUT PALADINX

We started on the attacking side. We never left it.

PaladinX exists because too much software is shipped by people who have never watched it fall over under attack. We came to building from testing — and it shows in everything we hand over.

CREDENTIALS

/ISO 27001–aligned internal processes
/OSCP-certified offensive security team
/24/7 security operations centre
/OWASP, PTES and NIST-based methodology
/Backed by an established technology group

Security-first is a sequence, not a slogan.

Most technology suppliers treat security as a final checkbox: build the thing, then ask someone to look at it. By then the risky decisions — how identity works, where data sits, who can see what — are already set in concrete.

We invert that. Our practice began in penetration testing, and offensive security still sets the standard for every other line of work. A threat model comes before a data model. An access review comes before a launch date. A test comes before a handover, not after an incident.

It is a slower way to start and a much cheaper way to finish.

Who you are actually hiring.

PaladinX is the security and engineering arm of a larger technology group. That matters commercially: contracts, insurance, continuity of staff, and the ability to keep a SOC staffed around the clock — none of which a lone consultant can offer.

The practice is led by our founder, a penetration tester by trade who still runs engagements personally. Testing is done by certified staff, and every report is peer-reviewed before it reaches you.

We work under NDA by default, and we will happily put you in touch with existing clients who can tell you what we are like to work with.

HOW WE WORK

Four rules we do not bend.

01

Scope in writing

Nothing is touched before rules of engagement are agreed and signed by both sides.

02

Criticals same day

If we find something that could be exploited today, you hear about it today — by phone.

03

Evidence, not adjectives

Every finding comes with reproduction steps, evidence and a rating you can defend to an auditor.

04

We stay until it is closed

A retest is included. A report full of open findings is not a finished job.

CONTACT

Book a free security assessment.

Tell us what you run and what worries you. We reply within four working hours, and the first conversation costs nothing.

Send an enquiry

We reply within four working hours. Your details are never shared, and we will sign an NDA before you tell us anything sensitive.

Working under NDA

Send a one-line note and we will return a signed NDA before you share anything sensitive.

WHAT HAPPENS NEXT

01We reply within four working hours
02A 30-minute call, NDA first if you prefer
03A scoped, fixed-price proposal within 48 hours

Find out what an attacker sees.

A free, no-obligation assessment of your external exposure — and a straight answer about what we would fix first.

Book a free assessment → Email the team
Book a free assessment →