Services
97 specialist services. Find the one that answers your problem.
11 practice areas, one standard: scoped, authorized, delivered with evidence. Starting prices are published on every service, and every page states what the engagement will not do.
I need to…
Matching services
All 97 services.
- From $1,499
Offensive / Testing
Web Application Penetration Testing
We attack your web application the way a skilled adversary would — safely, under a signed scope — and hand you a clear map of every exploitable weakness. You get proof, business impact and a fix-it plan, not a raw scanner dump.
Signed authorizationFree tool pairs - From $1,499
Offensive / Testing
API Penetration Testing
APIs are where modern breaches happen. We test your REST, GraphQL and gRPC endpoints for broken authorisation, data leakage and logic flaws, so the interfaces powering your apps and partners can't be turned against you.
Signed authorizationFree tool pairs - From $1,499
Offensive / Testing
Mobile Application Penetration Testing
Your mobile app runs on devices you don't control. We test iOS and Android builds for insecure storage, weak crypto, and backend flaws, covering the app, its APIs and the data it leaves behind.
Signed authorization - From $1,499
Offensive / Testing
External Network Penetration Testing
We probe your internet-facing perimeter the way an outside attacker would, finding exposed services, weak configurations and forgotten assets before someone else does. The result is a clear picture of your true attack surface.
Signed authorizationFree tool pairs - From $1,999
Offensive / Testing
Internal Network Penetration Testing
Assume an attacker is already inside — a phished laptop, a rogue device, a malicious insider. We test how far they could get, showing you the lateral-movement paths and privilege escalations that turn one foothold into a full compromise.
Signed authorization - From $1,299
Offensive / Testing
Wireless Network Penetration Testing
Your Wi-Fi is a doorway that reaches beyond your walls. We test wireless networks for weak encryption, rogue access points and guest-network leakage, so an attacker in the car park can't reach your corporate network.
Signed authorization - From $8,999
Offensive / Testing
Red Team Engagement
A full-scope, goal-oriented simulation of a real adversary. We combine digital, physical and human attack paths to reach an agreed objective — and show whether your people, processes and technology would actually detect and stop us.
Signed authorization - From $6,999
Offensive / Testing
Purple Team Engagement
Red and blue working side by side. We run realistic attack techniques while your defenders watch, measure and tune detection in real time — turning a single test into a lasting uplift in your detection coverage.
Signed authorization - Fixed — $1,499
Offensive / Testing
Phishing Simulation Campaign
Most breaches start with an email. We run realistic, ethical phishing campaigns against your staff to measure real susceptibility and turn every click into a teachable moment — building a human firewall, not blame.
Signed authorizationFree tool pairs - Fixed — $999
Offensive / Testing
OSINT Exposure Assessment
We see your organisation the way an attacker doing reconnaissance would — leaked credentials, exposed documents, revealing metadata and forgotten assets — using only public sources. Then we help you shrink that footprint.
Signed authorizationFree tool pairs - From $1,499
Offensive / Testing
Secure Source Code Review
Some flaws only reveal themselves in the code. Our experts read your source — by hand, guided by tooling — to find vulnerabilities, insecure patterns and design weaknesses that black-box testing can miss.
Signed authorization - From $1,499
Offensive / Testing
Security Architecture Review
The cheapest vulnerabilities to fix are the ones you design out. We review your system architecture against threats and best practice to find structural weaknesses before they become expensive incidents.
Signed authorization - From $2,499
Offensive / Testing
Reverse Engineering & Binary Analysis
When you need to understand what a binary really does — your own software, a vendor component or suspicious code you're authorised to examine — our analysts take it apart to reveal hidden behaviour, weaknesses and risks.
Signed authorization - From $3,499
Offensive / Testing
Adversary Emulation & Attacker-Perspective Advisory
Understand exactly how a determined criminal would target you — their tools, techniques and decision-making — replicated defensively under contract. It's the attacker's mindset, applied to make you harder to hit.
Signed authorization - From $2,999
Offensive / Testing
Penetration Testing as a Service (PTaaS)
Continuous, subscription-based penetration testing instead of a once-a-year snapshot. Every release, every major change, gets expert eyes — with findings delivered through your portal as we confirm them, not weeks later in a PDF.
Signed authorizationFree tool pairs - From $4,999
Offensive / Testing
Bug Bounty Program Management
A bug bounty program without expert triage becomes an expensive noise machine. We design, launch and run your program — scoping, policy, researcher communications and triage — so your engineers only ever see real, deduplicated, prioritised vulnerabilities.
Advisory engagement - From $2,499
Defense & MDR
Managed Detection & Response (EDR/XDR)
Our analysts watch your endpoints and cloud around the clock, so threats are caught and contained in minutes, not months. You get an expert SOC team and modern EDR/XDR tooling without building either yourself.
Signed authorization - From $2,499
Defense & MDR
SIEM-as-a-Service
Centralise your logs and turn them into detections without the pain of running a SIEM yourself. We design, deploy and manage the platform, engineer the detections and keep the signal high and the noise low.
Signed authorization - From $2,999
Defense & MDR
SOC-as-a-Service
A complete security operations centre, delivered as a service. People, process and technology working together to monitor, detect and respond around the clock — enterprise-grade defence without the enterprise build-out.
Signed authorization - From $1,999
Defense & MDR
Proactive Threat Hunting
Alerts catch known threats; hunting finds the ones already inside that slipped past. Our hunters proactively search your environment for signs of compromise using hypotheses, intelligence and deep telemetry analysis.
Signed authorization - From $799
Defense & MDR
Threat Intelligence & Exposure Monitoring
Know when your credentials, data or brand surface where they shouldn't. We monitor lawful sources — including breach corpora and criminal-forum chatter — for exposure relating to your organisation, and alert you early.
Signed authorizationFree tool pairs - From $1,499
Defense & MDR
DDoS Defense & Resilience
Keep your services online when someone tries to flood them offline. We design and implement layered DDoS protection and test your resilience, so volumetric and application-layer attacks don't take down your business.
Signed authorization - From $3,499
Defense & MDR
Zero Trust Architecture Design
Move beyond the old castle-and-moat model to 'never trust, always verify'. We design a pragmatic Zero Trust architecture for your organisation — identity-centric, least-privilege and staged so it's achievable, not aspirational.
Advisory engagement - Fixed — $799
Defense & MDR
Firewall Security Review
Firewall rules accumulate cruft over years — overly permissive rules, forgotten exceptions, risky any-any entries. We review your firewall configuration and ruleset to tighten access and shrink your attack surface.
Signed authorization
Verified Solvex Specialist
Verified by SolvexDirect specialist contact for Solvex engagements
What this means. An authorized Solvex administrator registered and approved this exact public identity. What it does not. Solvex has not inspected the account on the platform, and this is not the platform's own verification.
Solvex specialists never ask for your passwords, recovery phrases, one-time codes, or payments to a personal account. Work, scope and invoices are agreed in writing through the official channels on this site.
Practice areas
- Offensive Security & Testing16Find the weaknesses before an attacker does. Authorized penetration testing, red teaming and adversary emulation across web, API, mobile, network, wireless and human layers.
- Defense & Managed Detection11Around-the-clock detection and response. Managed EDR/XDR, SIEM and SOC-as-a-Service, threat hunting, DDoS defense and hardening that keeps attackers out.
- Governance, Risk & Compliance14Prove your security to auditors, customers and regulators. ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS readiness, vCISO leadership and the programs that keep you compliant.
- Incident Response & Forensics9Under attack or already breached? 24/7 incident response, digital forensics, malware analysis, ransomware recovery and the readiness work that makes the next incident smaller.
- Cloud & DevSecOps Security12Secure what you ship and where you run it. Cloud penetration testing, posture management, container and Kubernetes reviews, CI/CD pipeline audits and infrastructure hardening.
- Web3 & Emerging Technology17Security for the frontier: smart-contract audits, DeFi and wallet testing, IoT and firmware analysis, OT/ICS assessments, threat modelling and expert consultation.
- Secure Product Engineering4Software built secure rather than tested afterwards. Flutter and mobile applications, SaaS platforms, APIs and backends — engineered with authentication, tenancy, audit and release hardening designed in from the first commit.
- Algorithmic & Quant Systems4Trading and quantitative infrastructure built like safety-critical software: execution engines, order state machines, risk gates and kill switches, with honest validation of what a strategy does and does not demonstrate.
- Reverse Engineering & Binary Analysis4Authorized analysis of software you own or are permitted to examine: binaries, firmware, mobile applications and malware. For compatibility, security research and incident response — never for circumvention.
- SOC & Detection Engineering3The operating model behind detection: SOC architecture, telemetry planning, detection-as-code, alert quality and the coverage assessment that tells you honestly what your monitoring can and cannot see.
- Data Recovery & Resilience3Getting data back, and proving you could. Authorized recovery and restoration engineering, ransomware clean-room rebuilds, and backup architecture verified by testing rather than by assumption.
How an engagement runs
Six steps. Each one leaves something you can check.
The same model for every authorized engagement, from a first assessment to incident response.
- 01
Intake
Tell us the system, the goal and the constraints. If the work is not a good fit, we say so before anyone is invoiced.
Start a conversation - 02
Scope and authorization
Written scope and signed authorization before anything is touched. Security testing runs only against systems you own or are contractually entitled to have tested.
Responsible testing policy - 03
Investigation or build
Specialists matched to the work. Findings are proven by hand — scanner output is a lead, never a finding.
- 04
Evidence
Every finding ties to something observed. When a report is issued, its evidence is frozen in the same transaction, so what backed the report cannot change afterwards.
How evidence is handled - 05
Delivery
A signed report: an Ed25519 signature over both the content and the file, with a short verification reference you can read down a phone.
How signing works - 06
Verification and retest
Anyone holding the report can verify it publicly without seeing its contents. Fixes are retested as part of the engagement — “fixed” means we confirmed it.
Verify a report