Understand the exposure.
Choose the right next step.
Technical testing asks how a system could be compromised. Compliance asks how your organisation manages security.
Human-led testing.
Manually verified findings.
- OSCP-certified testers
- Written testing boundaries
- Actionable remediation
Six services. Clear boundaries.
Human-led investigation, manually verified findings and practical remediation. Each service has its own scope, prerequisites and limits.
Web applications
Authenticated testing of SaaS products and web applications across your agreed roles.
Explore testing 02Mobile applications
Security testing for iOS and Android apps, from local data to the backend calls in scope.
Explore testing 03APIs
REST and GraphQL testing focused on object-level access and token boundaries.
Explore testing 04Networks
External and internal testing with explicit host ranges and segmentation goals.
Explore testing 05Cloud environments
Controlled attack-path testing across cloud identities, workloads and data access.
Explore testing 06AI applications
Testing for AI applications, retrieval systems and agents, focused on data boundaries.
Explore AI securitySix services. No certificate we cannot issue.
Readiness work prepares you for the body that certifies, audits or attests. We are not that body.
ISO 27001 readiness
Clause-by-clause gap report and Statement of Applicability draft.
Explore the serviceSOC 2 readiness
Criteria selection, gap report and an auditor-ready evidence index.
Explore the serviceGDPR and Privacy Act readiness
Data map, transfer mechanisms and a tested breach process.
Explore the servicevCISO services Australia
A named security owner, a written monthly report and a prioritised roadmap.
Explore the serviceEssential Eight assessment and uplift
Control-by-control maturity report against the November 2023 ASD model.
Explore the servicePenetration testing to CREST-aligned methodology
Scoped testing, manual validation and a report structured to a recognised methodology.
Sorami is not a CREST member company. We follow a CREST-aligned methodology. If your procurement requires a CREST member supplier, tell us before you engage.
Explore the servicePractical answers.
Do we need a penetration test or a readiness assessment?
They answer different questions. A test asks whether a specific system can be broken. A readiness assessment asks whether your organisation can evidence a control to an auditor. If a customer sent a questionnaire, you usually need readiness. If they named a test, you need the test.
Can one engagement cover both?
They are scoped separately and priced separately, because the access, the people and the deliverable all differ. Many teams run readiness first, then test the system the auditor cares about, so the test report becomes evidence.
Will a penetration test get us SOC 2 or ISO 27001?
No. A test produces evidence that supports a control. The certificate comes from an accredited certification body or a licensed CPA firm, and Sorami is neither. We prepare you for them.
How quickly can you start?
Scoping is a 30-minute call and a written scope within one business day. Start dates depend on access readiness rather than our calendar, and access is usually what delays a start.
Not sure which kind of help you need?
Tell us what prompted the conversation. We will distinguish testing from engineering or advisory before discussing a scope.
Last reviewed: