Yes. DongIT performs pentests on a wide range of technologies. We test not only traditional web applications, but also mobile apps, APIs, cloud environments, network infrastructure and OT systems.
Web applications
Our most commonly performed pentest type. We test both classic server-rendered applications and modern single-page applications (SPA) and progressive web apps (PWA). Our findings are mapped to OWASP Top 10 (2021), OWASP ASVS and relevant CVE databases.
Mobile applications (iOS and Android)
We test native iOS apps (Swift, Objective-C), native Android apps (Kotlin, Java) and cross-platform apps (React Native, Flutter, Xamarin). For mobile tests we work with test apps via TestFlight (iOS), Firebase App Distribution or direct APK installation. Our testing framework aligns with OWASP Mobile Top 10 and OWASP MASVS, covering both the client app and its associated backend API.
APIs (REST, GraphQL, SOAP)
APIs are an increasingly large attack surface. We test REST APIs (with or without OpenAPI/Swagger specifications), GraphQL endpoints and SOAP services. Testing aligns with OWASP API Security Top 10 (2023) and covers authentication, authorization, business logic, rate limiting and data exposure.
Network infrastructure and cloud environments
External network pentests for internet-facing infrastructure. Internal network pentests via VPN or jump host. Cloud configuration assessments on Azure, AWS and GCP including IAM, storage, network segmentation and serverless components. Our pentesters work daily with cloud-native architectures and Kubernetes environments.
OT systems and industrial environments
For organizations in energy, water, manufacturing and transport, we perform OT pentests. We follow strict safety protocols to protect production continuity and work closely with your OT operations team.
Other assessment types
- Source code reviews. Manual analysis of your source code for vulnerabilities only visible at code level.
- Red team assessments. Realistic attack simulations with social engineering and physical intrusion.
- Phishing simulations. Awareness testing of your employees.
Our pentest scope is always tailored to your specific situation. Contact us for a complimentary scoping conversation, or view our pentest packages.
Nederlands