Skip to content

Offensive security · E-commerce

Controlled Breach

Penetration Testing for E-Commerce

Know your vulnerabilities before attackers do. We break into your store the way a real adversary would — under written authorization, with a defined scope, and a report your team can act on the same week.

  • 48–96 h of testing
  • Report + live session

Fixed price after the scoping call, no surprises.

01 — The problem

The Silent Threat

Scanner results are incomplete. Logic flaws, authorization bypasses and business logic abuse stay hidden until someone with intent goes looking.

  • 01

    Scans miss what matters

    Automated tools check signatures, not intent. Coupon stacking, price tampering and checkout abuse never show up in a scan report.

  • 02

    Vulnerabilities go unpatched

    Without proof of impact, findings sit in a backlog. Every week a flaw stays open is a week someone else can find it.

  • 03

    Fraud losses accumulate

    Chargebacks, refund abuse and account takeovers erode margin quietly. The cost appears in finance long before it appears in IT.

02 — Approach

We don't stop at the scanner.

PTES methodology, authorized, legal-first. Automated tools are where we start, not where we stop: every finding is verified and taken as far as a real attacker would go.

  1. Offensive Mindset

    No scan-and-forward. We chain weaknesses together the way an adversary would, and show you exactly how far they lead.

  2. Precision Focused

    PTES methodology. Eight phases, zero guessing. Every finding comes with severity and reproducible evidence.

  3. Built on Trust

    Authorized, legal-first, GDPR and NIS2 aligned. Clear rules of engagement before a single request touches your systems.

03 — Compliance

Regulatory Alignment

Testing is only useful if it supports the obligations you already have. Every report maps findings to the frameworks your auditors ask about.

  • GDPR

    Personal data encountered during testing is minimized, never exfiltrated and handled under a data processing agreement. Findings support your Article 32 security obligations.

  • NIS2

    Regular, documented security testing is part of the risk management measures NIS2 expects. Reports are structured to serve as evidence for your management body.

  • PCI-DSS

    Assessments cover the payment flow and its surrounding attack surface, and can be scoped to support Requirement 11 penetration testing evidence.

  • ISO 27001

    Findings and remediation tracking map to Annex A technical controls, giving your ISMS a clear record of tested and verified safeguards.

All assessments conducted under written authorization.

04 — Methodology

PTES — 8 Phases

The Penetration Testing Execution Standard, applied end to end. You always know which phase we are in and what comes next.

  1. 01

    Planning & Scoping

    Objectives, targets and rules of engagement, signed.

  2. 02

    Reconnaissance

    Public footprint, tech stack and third-party exposure.

  3. 03

    Surface Mapping

    Every endpoint, role and flow your store exposes.

  4. 04

    Vulnerability Analysis

    Logic, authorization and injection paths ranked by risk.

  5. 05

    Exploitation (PoC)

    Controlled proof that the flaw is real and reachable.

  6. 06

    Post-Exploitation

    What an attacker could reach, take or change next.

  7. 07

    Reporting

    Executive summary plus technical detail per finding.

  8. 08

    Remediation Support

    Fix guidance and a retest to confirm closure.

05 — Team

Who runs the engagement

Gabriel Delmelo

Founder & CEO · Security Analyst

5 years as a systems administrator and a Master's degree in Cybersecurity. Founded DELSTRIKE to bring offensive security testing to online stores.

LinkedIn profile

06 — Packages

Engagement Models

Three scopes, one standard of rigor, each package adding capabilities on top of the previous one.

Fixed quote after the scoping call

  • Fast Coverage

    Essentials

    Turnaround
    48 hours
    Modality
    White-box
    We work with the documentation and access you provide, so we spend less time on reconnaissance and more on finding flaws.
    Phases included
    1–4

    What you discover

    • Common web vulnerabilities (injection, XSS) on your main routes
    • Insecure configuration: headers, TLS, CORS, cookies
    • Exposed information: versions, keys, public files
    • Weaknesses in login and session handling

    What's included

    • Reconnaissance
    • Surface mapping
    • Top 3 vulnerabilities verified with reproducible evidence
    • Remediation guide
    • Live session to walk through results

    Who it's for

    • Stores running their first audit
    • Small teams that need to prioritize
    • Before a launch or redesign
  • Most requested

    Comprehensive

    Professional

    Turnaround
    72–96 hours
    Modality
    Grey-box (default)
    Phases included
    1–5 (exploitation included) and 7; phase 8 as remediation support
    Post-exploitation is reserved for Enterprise.

    What you discover

    • Business logic flaws: prices, coupons, stock, refunds
    • Access to other customers' data (IDOR, authorization)
    • Abuse of checkout and payment flows
    • APIs and integrations: ERP, marketplaces, webhooks

    What's included

    • Controlled exploitation of findings (phase 5)
    • Logic flaws deep dive
    • Business impact analysis
    • Remediation roadmap
    • Live session, remediation support and retest (phase 8)

    Who it's for

    • Established stores with recurring sales
    • Annual audits or partner requirements
    • After major checkout or integration changes
  • Full Realism

    Enterprise

    Turnaround
    TBD
    Estimated together with you after the scoping call.
    Modality
    Black-box (maximum authenticity)
    Phases included
    1–8, including post-exploitation

    What you discover

    • Full attack chains from the outside, with no prior knowledge
    • How far an attacker gets after the first foothold
    • Impact on operations, payments and continuity
    • Exposure of infrastructure and third-party services

    What's included

    • Business continuity impact
    • Executive presentation and remediation strategy

    Who it's for

    • High-volume or business-critical operations
    • Compliance needs: NIS2, PCI-DSS, insurers
    • Boards that need an executive view of risk

07 — Next steps

What happens after you request the assessment

  1. Scoping call

    We write to you to propose a short call to understand your store, platform and goals. We agree on targets, modality and testing window.

  2. Proposal and written authorization

    You receive a fixed-price proposal and the rules of engagement. Nothing is tested until the authorization is signed.

  3. Execution and delivery

    We run the agreed PTES phases, alert you immediately on critical issues and deliver the report in a live session.

08 — FAQ

Frequently asked

What's the difference between black-box, grey-box and white-box?

Black-box means we start with no prior knowledge, exactly like an outside attacker. Grey-box gives us test accounts or partial documentation so we can reach deeper flows faster. White-box includes source code or architecture access for the most thorough coverage in the time available.

Is this service destructive?

No. We agree on rules of engagement before starting, avoid denial-of-service techniques, and use proof-of-concept payloads that demonstrate impact without damaging data. Production testing windows can be scheduled to suit your traffic.

How long until I get results?

48 hours of testing for Essentials and 72–96 hours for Professional, followed by the written report. Enterprise timelines are estimated together with you after the scoping call. Critical issues are reported immediately, not at the end.

What if you find critical vulnerabilities?

We stop, notify your designated contact the same day with evidence and an interim mitigation, and agree on how to proceed before continuing.

Do you provide remediation support?

Yes. Every report includes fix guidance per finding, and we retest remediated issues to confirm they are closed.

Is this compliant with GDPR/NIS2?

Engagements are run under a signed authorization and a data processing agreement, with data minimization by default. Reports are structured to serve as evidence for GDPR Article 32 and NIS2 risk management obligations.

09 — Contact

Let's Talk

Leave your email, platform and the package you're interested in. We'll write back to propose a scoping call.

Package

Purpose: to answer your request and prepare the scoping call. Legal basis: your consent (GDPR art. 6.1.a), which you can withdraw at any time.

Would you rather write to us directly?contact@delstrike.com