years building and scaling production software
Application security for software teams
Automation scales everything.
Including risk.
Perspican provides web and API penetration testing, validates scanner and AI findings, and turns confirmed vulnerabilities into practical fixes.
Working internationallyRemote delivery in English
Why now
There is almost always a deadline.
- A customer's security questionnaire asks for a recent third-party penetration test
- A release is going out and nobody has looked at it from the outside
- An auditor wants evidence for ISO 27001 or SOC 2
- Investor due diligence has started
- Something happened, and you need to know what else is exposed
All five come back to the same thing: people gave you their data, and someone is asking what stands between it and the outside.
A pentest puts evidence behind your answer.
Services
Start with the problem in front of you.
Web & API penetration testing
In-depth testing of web applications, APIs and the supporting cloud paths that matter to the product.
Finding validation & remediation
Validate scanner, AI and previous assessment findings against the real code, then make the fix practical.
Ongoing product security support
Review a sensitive change, work through a remediation or verify a fix without repeating a full pentest.
When a verified fix requires production code, remediation engineering is available as a scoped add-on.
Who does the work
Accountability, built in.
hands-on offensive security certification from OffSec
independent consultancy operating since 2018
Automated findings in 2026
More findings than ever. Which ones actually matter?
You already run scanners, SAST and probably an agent or two. They produce claims, and the better they get, the more convincing the wrong ones look.
Finding candidates is cheap now. An agent will sign in as three different roles, send an invitation and accept it from another tenant, then do that four hundred times before a person has finished testing it once.
Some of what comes back is straightforward: the exploit works, the boundary is clear, the issue is real.
The rest turns on a decision the product never recorded. Whether an invitation should cross tenants, whether a workflow should allow a state transition: that is product intent, and it lives with the people who built it.
Out of all those candidates, I bring you the few worth an engineer’s afternoon, already reproduced, each with the business impact stated and one question left: was this supposed to be allowed? The rest never reach your team. I made that call, you can ask me why, and the answer is the same tomorrow.
How an engagement runs
Following the risk all the way through.
The pentest covers the exposed surfaces and confirms what an attacker can actually do. What comes back is work your engineering team can act on.
- 01Find the weak points
The pentest covers the product and its real entry points.
- 02Verify what can happen
What can actually be exploited is confirmed, along with its impact.
- 03Make the fix practical
You won’t be left wondering what to do. You get exactly where the issue sits in your code, with a suggested solution.
From a client
Some issues require a closer look.
“Giuseppe was able to identify hard to exploit security issues that went undiscovered in the previous 3 pentests performed by 2 different providers.”
Could there be more to find?
Let's look at the system to define the work around your objective and deadline.
Prefer to write directly? [email protected]

