Citizen portal assessment
Multi-role testing across citizen, caseworker and administrative accounts, with eligibility logic and cross-access tested.
Benefits portals, licensing systems, tax filing, records access — services that must be open to everyone by design, running on estates that were often built decades apart and connected later.
AIPTx tests them repeatedly rather than annually, and produces evidence written for the packages your authorising officials already require.

Government estates are the accumulated result of every technology decision made since computing arrived, and almost none of those decisions can be reversed.
A modern citizen-facing portal fronts a services layer, which fronts a records system built in a different era, which integrates with another agency's system under an arrangement documented in a memorandum rather than in code. Each layer was secured according to the assumptions of its own time. Three characteristics shape security here.
The service cannot be selective about who reaches it. A commercial platform can restrict access to customers.
A benefits portal must be reachable by anyone eligible, from any device, often including people with limited digital access. Rate limiting and bot mitigation are constrained by an obligation to serve. Consequence is measured in trust as well as data. A breach of a citizen service is not only a data incident. It is a political event, and it damages participation in the service itself. Evidence is procedural. Authorisation packages, continuous monitoring obligations and audit cycles mean that security work which cannot be evidenced does not count, regardless of how good it was.
Replacement programmes run for years and are funded politically. Security has to work with what exists, which means knowing precisely what exists.
Data crosses organisational boundaries under agreements that predate current threat models. Each connection is a trust relationship, and the receiving system frequently assumes the sending one has already validated.
Determining who someone is and what they are entitled to is the core function of many public services, and it is business logic, the class with no signature. Eligibility manipulation and status escalation are the abuses that matter here.
Agencies accumulate domains, subdomains and services across programmes, campaigns and departments. Consolidation is rare. Assets outlive the programmes that created them.
Much of the estate is built and operated by third parties, and the boundary of responsibility is often clearer in the contract than in the network.
Annual or biennial assessment against systems that receive continuous minor changes, with the gap covered by nothing.
The same tests, the same depth, the same output format every run, which is what makes trend comparison meaningful across an authorisation period rather than a set of unrelated reports.
Findings map to NIST and CIS alongside ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA, with control assessment and gap analysis in the reports. For agencies whose authorisation frameworks are built on NIST control families, this is the mapping that does the work.
Reconnaissance enumerates subdomains, ports, services and endpoints and fingerprints what responds, which for a large agency estate typically surfaces services nobody has an owner for.
Internal network assessment via a Docker-deployed agent covers internal IP ranges and CIDR blocks: port and service detection, version detection, CVE matching, TLS posture and default credentials. Where a system cannot be changed, knowing its exact exposure is what lets compensating controls be placed accurately rather than generously.
Business logic testing in Standard mode, with race conditions and complex multi-step chains in Deep mode. Multi-role configuration allows a citizen role, a caseworker role and an administrator role to be cross-tested against each other.
Every confirmed finding carries the exact HTTP request, the response proving it worked, and a reproducible curl command, with CVSS 3.1, a CWE class and control mapping. Status is tracked as open, fixed, accepted or false_positive, with attribution and timestamps, which is the form continuous monitoring obligations actually require.
Alongside ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA, with gap analysis.
AI risk engineSubdomain and asset enumeration, service and version fingerprinting across large estates.
External attack surface managementDocker-deployed agent, outbound connectivity only, across IP ranges and CIDR blocks.
Citizen, caseworker, administrator, with bearer, basic, cookie, custom header and OAuth2/OIDC support.
Web application securityEligibility manipulation, status escalation, IDOR, privilege escalation.
Autonomous pentestingREST via OpenAPI or Swagger, GraphQL with introspection, gRPC with proto files, for inter-agency and partner integrations.
Open, fixed, accepted, false_positive, each change carrying a person, a date and a reason.
PDF, HTML, JSON, CSV and SARIF, plus a REST API for feeding findings into an existing governance system.
Multi-role testing across citizen, caseworker and administrative accounts, with eligibility logic and cross-access tested.
Enumerating the full external surface across departments and legacy programmes, then assessing what is found.
A Deep assessment before an authorisation review, with NIST control mapping and retest history attached.
Scheduled assessment producing the ongoing testing record the obligation requires.
Assessing the API surface exposed to another agency or a contractor before enabling the connection.
Independently assessing a system delivered by a supplier before acceptance.
Yes. Findings map to NIST and CIS controls alongside ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA, with control assessment and gap analysis included in reports.
Yes, at the layer they expose. Internal network assessment covers hosts and services (ports, versions, CVE matching, TLS posture, default credentials) without requiring any change to the system. Knowing the exact exposure is what allows compensating controls to be placed precisely.
Assessments run on a schedule with consistent methodology, and reports carry trend comparison against previous runs. Finding status is tracked with attribution and timestamps, so the record shows not just what was found but what was done about it and by whom.
Findings export as JSON and CSV and are available through the REST API. Each carries CVSS 3.1, a CWE class, control mapping and full status history.
Consistent, repeatable testing with NIST control mapping and evidence written for the process you already run.
Scope verified before any test runs · Destructive actions off by default
Same engine, different threat model, different auditor. Each page covers the systems, regulations and attack paths that sector actually lives with.
Payment flows, lending decisions, account servicing, open banking APIs — the logic that handles money is the logic attackers study hardest. It is also the logic no signature database describes.
ExplorePatient portals, scheduling systems, clinical APIs, payer integrations: all of it holds data that carries a lifetime of consequence if it leaks, and much of it runs on systems that cannot be taken offline for a test.
ExploreAlmost nobody breaks into a plant by attacking a controller. They arrive through a corporate account, a supplier portal, an ERP integration or an exposed remote access service, and then walk into a network that was designed for reliability, not for containment.
ExploreThe vulnerabilities that cost retailers money are rarely exotic. A discount that stacks when it should not. A price accepted from the client. A gift card balance that survives a concurrent request. A loyalty account reachable from another customer's session.
ExploreEvery enterprise deal arrives with a questionnaire, a SOC 2 request and someone technical asking when you last tested. Meanwhile you ship on Tuesday and again on Thursday, and the last pentest describes a product that has since changed twice.
ExploreA single authorisation flaw in a subscriber portal is not one exposed account. At operator scale it is a data set — and the same flaw in a provisioning API is an operational one.
ExploreA department stood up a project site in 2019. A research group runs its own server. A faculty subdomain points at infrastructure that was decommissioned two years ago. None of it went through central IT, and all of it is reachable.
ExploreClients do not retain a firm because of its document management system. They retain it on the assumption that what they share stays privileged — and increasingly they audit that assumption before instructing.
Explore