Services

Four fronts, one way of working.

We carry out manual exploitation with verifiable evidence for every finding, delivering reports technical teams can act on without interpretation. The scope, the rules of engagement and the testing window are set transparently and in writing before any activity begins.

01

Offensive security

Manual pentesting against the surface you actually expose. Real exploitation and a reproducible proof of concept for every finding, not a list of scanner output.

What we cover

  • Web applications

    Authentication, access control, business logic and injections. Coverage guided by the OWASP Top 10 and OWASP ASVS, with chained exploitation wherever it exists.

  • API

    REST, GraphQL and SOAP. Object- and function-level authorization, excessive data exposure, rate-limiting abuse. Reference: OWASP API Security Top 10.

  • Mobile

    Android and iOS. Insecure local storage, certificate pinning, anti-tampering protections and the backend sitting behind the app.

  • Cloud

    AWS, Azure and GCP. IAM review and privilege escalation, exposed buckets and storage, poorly segmented networks and secrets leaked in configuration.

  • AI and LLM

    Direct and indirect prompt injection, system prompt leakage, RAG context poisoning and tool or agent abuse. Reference: OWASP Top 10 for LLM Applications.

02

Code analysis

Reviewing the application from the inside and from the outside. Every automated alert is manually validated before it reaches the report: without triage, a SAST run is mostly noise.

What we cover

  • SAST

    Static analysis over source code. Catches insecure patterns and tainted data flows before deployment, including code no dynamic test ever reaches.

  • DAST

    Dynamic analysis against the running application. Finds what only shows up live: environment configuration, sessions and runtime behaviour.

  • MAST

    Mobile-specific analysis, static and dynamic, over the binary and the traffic. Reference: OWASP MASVS and MASTG.

03

Banking core

Assessment of financial platforms, where failure is not a data leak but an altered transaction. The team brings prior experience across Mexican SOFIPOs, insurers and banks. Always performed under an agreed window and signed rules of engagement.

What we cover

  • Core platform

    Integrity of transactional logic, dual-control checks, segregation of duties and traceability of sensitive operations.

  • Interfaces and messaging

    Integration channels and financial messaging (ISO 8583, ISO 20022, SWIFT): field validation, replay, amount tampering and idempotency control.

  • Channels and perimeter

    Online banking, the mobile app and the APIs behind them, along with the network segmentation separating the core from the rest of the organization.

04

PCI DSS analysis

Technical work on the cardholder data environment (CDE) so the formal assessment arrives without surprises.

What we cover

  • Gap analysis

    Review of the CDE against the PCI DSS v4.0 requirements, with the real distance to compliance and a prioritized remediation plan.

  • PCI-scoped pentest

    The internal and external penetration test required by Requirement 11.4, with methodology, scope and evidence documented the way the standard asks for.

  • Segmentation testing

    Verification that segmentation controls genuinely isolate the CDE, per Requirements 11.4.5 and 11.4.6, to support scope reduction.

Argus RK is neither a QSA nor an ASV. We perform the technical work and the penetration testing the standard requires, and prepare the evidence; the formal assessment and the signing of the RoC or SAQ belong to an accredited QSA, and the quarterly external scan to an ASV.

Does any of this match what you need?

Tell us the scope and we send back a technical proposal in under 48 hours.

Request an audit