Penetration Testing
Hands-on, goal-driven testing against your systems. We go after real objectives the way an attacker would, then hand you the proof, the impact, and a clear path to closing each finding.
Security engineers who would rather fix a problem than write a report about it. Penetration testing, application security, DevSecOps, and vulnerability work — done hands-on, around how your environment actually runs.
From the code your developers write to the network it runs on — we test, break, and harden real systems, and we stay until every finding is closed. Take one discipline or the whole chain.
Hands-on, goal-driven testing against your systems. We go after real objectives the way an attacker would, then hand you the proof, the impact, and a clear path to closing each finding.
We test the things that break in the real world: broken authentication, access-control gaps, injection, and business-logic flaws that only show up when you push the app somewhere it did not expect to go.
We read the code behind the app, not just the responses it returns. Auth and session handling, input trust boundaries, unsafe deserialization, and the quiet mistakes a scanner will never flag.
We move security into the build, so problems get caught before they ship. Scanning, secrets handling, and policy checks wired into your pipeline — without slowing your developers down.
Most of your codebase is somebody else's. We map what you actually ship — dependencies, build steps, and artifacts — then make it verifiable with SBOMs, signing, and a trust chain you can prove.
Scanners hand you thousands of findings. We tell you which ones actually matter in your environment, what can wait, and what to fix today — so your team works a short list, not a 400-page export.
Identity is the new perimeter and most breaches walk through it. We review how access is granted across your cloud and directory, then harden the paths that let one account become all of them.
We map what is really on your network — not what the diagram claims — and find the misconfigurations, soft spots, and forgotten boxes an attacker would use to get a foothold.
A full-scope test of how your people, tooling, and defences hold up against a determined adversary. Quiet and realistic, built to answer one question: would you catch us?
Most sites get secured after they are built. We work the other way round: designed and built with hardened defaults, clean dependencies, and no attack surface the site never needed — delivered through our studio, WEBFORIT.
Every finding comes with a remediation path we have tested — and we retest after you fix, because a closed ticket should mean the problem is actually gone.
Structured, transparent, and designed to deliver measurable outcomes — aligned with ISO 27001, NIST, and SOC 2.
We audit your posture, map your infrastructure, and identify gaps against ISO 27001, NIST, and SOC 2. You get a prioritised risk register.
Vulnerability scanning, attack-surface mapping, and threat modelling tailored to how real adversaries would target your organisation.
We deploy controls, SIEM configurations, Zero Trust policies, and DevSecOps pipelines — working alongside your team, not around it.
Ongoing monitoring, quarterly compliance reporting, and incident response planning. Your posture improves continuously, not just at audit time.
We started in Arad in 2019 on a simple principle: stay small enough that you always know exactly who is on your account. No layers of account managers, no handing your project to whoever happens to be free — the engineer who scopes your work is the one who runs it, start to finish.
We test, script, and break things for a living. When we hand you a finding, it comes with proof and a fix we have actually tried — not a line copied out of a scanner. That is the whole point of working with people instead of a tool.
That holds whether you are a five-person startup shipping your first product, an agency that needs a build reviewed before it goes live, or an established team wanting a second pair of eyes on a programme you already run.
Some things stay redacted. NDA by default.
The engineer who scopes your test is the one who runs it. No handoffs.
Every finding comes with a fix we have tested — not just a severity score.
We retest after you remediate, so a closed ticket actually means closed.
NDA on request. What we find stays between us.
Security advice is only worth the experience behind it. So here is the person behind it — no stock photos, no anonymous “our experts”.
Founder & Security Engineer
Security engineer working across both sides of the discipline — building the pipelines and identity infrastructure software ships through, and testing systems from the attacker's side to find where they break.
Research on insecure deserialization in web applications — OWASP A08:2025, Software & Data Integrity Failures.
Our web design and development studio. Same engineers, the other side of the desk — building sites and web applications with hardened hosting, dependency hygiene, and secure defaults from the first commit, instead of bolting security on after launch.
The things people ask before the first call. If yours is not here, just send it — we answer within 24 hours.
Ask us directlySECFORIT provides hands-on cybersecurity consulting — penetration testing, application and API security, secure code review, DevSecOps integration, cloud and identity hardening, and vulnerability management. We are based in Arad, Romania and serve clients across Europe.
Yes. Every engagement starts with a no-obligation discovery call where we listen, assess your security posture, and propose a tailored plan. Response within 24 hours.
We work with organisations of all sizes across Europe — startups shipping their first product, agencies and SaaS teams, and established companies with existing security programmes. Our methodology adapts to your environment, compliance requirements, and risk appetite, so a small team gets the same engineering attention as an enterprise.
We follow a proven four-phase model: Discovery & Assessment, Threat Modelling, Implementation, and Continuous Protection. Structured, transparent, and designed for measurable outcomes aligned with ISO 27001, NIST, and SOC 2.
Both. We test running systems the way an attacker would, and we read the code behind them. Secure code review is OWASP-aligned and covers authentication and session handling, injection, access control, unsafe deserialization, and the dependency and build chain that ships the code.
Yes. We wire security into the build itself — SAST and SCA gates, secrets management, infrastructure-as-code scanning, SBOM generation with CycloneDX or SPDX, and artifact signing and trust chains — so problems are caught before they ship rather than after.
The engineer who scopes your engagement is the one who runs it. SECFORIT is led by Adrian-Răzvan Lișman, a security engineer with an M.Sc. in Cybersecurity Engineering, working across offensive testing, DevSecOps, and vulnerability management. There are no handoffs to junior staff and no account-manager layer between you and the person testing your systems.
Yes — through WEBFORIT, our web design and development studio at webforit.ro. It is the same engineering practice on the build side: sites and web applications developed with hardened hosting, dependency hygiene, and secure defaults from the first commit.
Every engagement starts with a no-obligation discovery call. We listen, assess, and propose a tailored plan — no generic checklists, no upselling. Response within 24 hours.