Datasheets

Every service explained

Technical summaries of each Payatu assessment - scope, methodology, deliverables, and the standards behind them. Built to hand to a colleague or attach to a budget request.
Featured Datasheet

Web Application Security Assessment

  • Scope: client-side, server-side, business logic, and APIs
  • Realistic attack and penetration methodology
  • Detailed reporting, mitigation, and retest
PDF:  
3
pages

Product Security Assessment

  • The whole product, firmware, app, cloud, radio and APIs
  • Threat modelling and exploitability testing across every product interface
  • Deliverables, severity model and retest policy
PDF:  
3
pages

Secure Code Review

  • Manual review depth on top of automated SAST
  • Logic anddesign flaws SAST misses, across the languages in your stack
  • Deliverables, severity model and retest policy
PDF:  
3
pages

DevSecOps Consulting

  • Security built into the CI/CD pipeline and SDLC
  • Shift-leftgates, tooling and secure-by-design practices developers accept
  • Deliverables,maturity view and engagement model
PDF:  
3
pages

IoT Security Assessment

  • Hardware, firmware, radio, companion app and cloud
  • Firmware extraction, interface and protocol testing, plus OWASP IoT coverage
  • Deliverables, severity model and retest policy
PDF:  
3
pages

Red Team

  • Objective-based adversary simulation across IT and OT
  • Mapped to MITREATT&CK, testing detection and response, not just prevention
  • Deliverables, attack narrative and retest policy
PDF:  
3
pages

Critical Infrastructure Security Assessment

  • Protocol-level OT testing under live-plant safetyconstraints
  • Aligned to IEC62443 and NIST SP 800-82, with NCIIPC and CEA context
  • Deliverables, severity model and retestpolicy
PDF:  
4
pages

Cloud Security Assessment

  • AWS, Azure and GCP configuration, IAM and workloadisolation
  • Misconfiguration and multi-tenant boundary review against CIS benchmarks
  • Deliverables,severity model and retest policy
PDF:  
4
pages

Mobile Application Security Assessment

  • Android and iOS apps and their backend API surface
  • OWASP MASVScoverage: storage, transport, runtime and platform interaction
  • Deliverables, severity model and retestpolicy
PDF:  
3
pages