Skip to content
Safestorm
Menu

Independent UK cybersecurity consultancy

Founder-led security testing built around real attack paths.

Safestorm provides independent penetration testing across applications, APIs, infrastructure, Active Directory and cloud environments—combining manual validation, controlled exploitation and clear remediation guidance.

What we solve

Turn technical weaknesses into clear business decisions

Unknown exposure

Map reachable systems and attack paths before they become incidents.

Unvalidated findings

Separate exploitable weaknesses from noise through expert manual validation.

Unclear priorities

Connect evidence to business impact and practical remediation.

Core services

Focused security assessments

Web Application Penetration Testing

Manual, risk-led testing of web applications, authentication journeys and business-critical workflows.

Explore service →

Internal Infrastructure Penetration Testing

Controlled testing of internal networks, systems and trust relationships to identify realistic paths to compromise.

Explore service →

External Infrastructure Penetration Testing

An attacker’s-eye assessment of internet-facing systems, services and remote-access infrastructure.

Explore service →

API Security Testing

Manual testing of REST, GraphQL and other APIs for authorisation, data exposure and business-logic weaknesses.

Explore service →

Cloud Security Assessments

Risk-led assessment of cloud identity, configuration, data exposure and paths to control-plane compromise.

Explore service →

Active Directory Security Assessments

Deep assessment of directory privilege, authentication and trust paths that could lead to domain compromise.

Explore service →

Why Safestorm

Direct technical ownership

  • Founder-led delivery: Felix remains involved from scoping and testing through reporting, debrief and retesting.
  • Real attack paths: controlled exploitation establishes whether separate weaknesses can produce a meaningful outcome.
  • Technical depth: six years of offensive-security experience across identity, infrastructure, applications, cloud and security-control validation.
  • Useful outcomes: evidence, business context and practical remediation are written for the people who must make and implement the decision.

Engagement process

  1. 01 Define assets, threats and assurance objectives
  2. 02 Agree authorisation, safety limits and communications
  3. 03 Map and validate realistic attack paths
  4. 04 Report, debrief, remediate and retest

Technical focus

Broad coverage, with depth where trust breaks down

Safestorm uses structured standards as a baseline, then follows identity, data and network relationships manually to find the attack paths that checklists miss.

Identity and Active Directory

Kerberos, NTLM, delegation, certificate services, trust relationships and indirect privilege paths.

Applications and APIs

Authentication, authorisation, tenant isolation, injection, server-side behaviour and business logic.

Infrastructure and cloud

Segmentation, credential exposure, IAM, external attack surface, lateral movement and control-plane risk.

Adversary behaviour and IPv6

Threat-informed attack paths, defensive visibility and unmanaged dual-stack network exposure.

Industries

Assessment grounded in your operating context

Healthcare and health technology
Professional services
Technology companies
SaaS providers
Retail and e-commerce
Small and medium-sized businesses

Frequently asked questions

Before an engagement

How is penetration testing different from a vulnerability scan?

A scan identifies potential issues automatically. A penetration test adds expert analysis, manual validation and controlled exploitation to establish real business impact.

Will testing disrupt our systems?

Testing follows agreed rules of engagement. Potentially disruptive activity is discussed in advance and only performed with explicit authorisation.

What do we receive?

An executive summary, detailed findings, evidence, risk ratings, practical remediation guidance and a technical debrief.

Who performs the testing?

Safestorm is founder-led. Felix remains directly involved from scoping through testing, reporting and debrief, so technical context is not lost between sales and delivery teams.

Which standards guide the assessment?

Coverage is shaped by the target and objective. Relevant references may include the OWASP testing guides, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, NCSC guidance and CIS Benchmarks. These support—not replace—expert judgement.

Do you provide retesting?

Retesting can verify that agreed fixes address the original weakness without introducing new risk.

Ready to understand your real exposure?

Tell us what you need to protect and what assurance you need. We will help define a proportionate assessment.

Request a Security Assessment