SentinelForge
Offensive Security · Est. 2017

We break the systems that shouldn't break in production.

A 22-person offensive-security firm working with regulated fintech, healthtech, and SaaS teams that need more than a checkbox pentest. CREST-certified. SOC 2 Type II attested. NDA in 15 minutes.

Request a scoping call    See services
217
Engagements delivered
14
CVEs disclosed in 2025
98%
Client renewal rate
15 min
Median NDA turnaround

What we actually do

Six service lines. All delivered by senior consultants — no offshoring, no juniors leading engagements.

01

Web application pentest

OWASP-aligned testing of your web application, API, and auth flow. Includes chained-exploit narrative, not just a scanner dump.

02

Cloud configuration review

AWS, GCP, and Azure. We hunt for the misconfigurations that automated tools miss: IAM privilege paths, cross-account trust, KMS key sprawl.

03

Red team engagement

Objective-based adversary simulation over 4–8 weeks. Assume-breach or full-scope. Includes detection & response evaluation for your SOC.

04

Source code review

Manual review of critical paths — authentication, authorization, cryptography, session handling — supplemented with SAST.

05

Threat modeling

Architecture-level review using STRIDE and attack trees. Best done during design, not after launch. Outputs feed your backlog directly.

06

Incident response retainer

24/7 on-call detection response with a 30-minute SLA. Includes tabletop exercises quarterly and one full IR simulation per year.

Why teams pick us over the Big Four

Senior-only delivery

Every engagement is led by a consultant with 8+ years in offensive security. No partner-and-forget model. The person who signs your scoping call is on the engagement.

Findings you can act on

Each finding includes a working proof-of-concept, an exact remediation snippet in your language, and a re-test window (30 days, free) after you push the fix.

Regulatory-ready reporting

Every report is structured to satisfy SOC 2 CC7, PCI DSS 11.3/11.4, HIPAA §164.308, and ISO 27001 A.12.6. Your auditor gets what they need without a second engagement.

No compliance-only theater

If we can't find something meaningful, we tell you. We'd rather lose the follow-on engagement than pad a report with low-severity nits to justify the invoice.

Our certifications and disclosures

The credentials that matter for regulated buyers.

CREST STAR

Threat intelligence-led penetration testing for financial services.

SOC 2 Type II

Attested 2025 by Prescient Assurance, no exceptions.

PCI QSA (partner)

Through our audit partner Coalfire for PCI scope validation.

ISO 27001

Certified since 2021 by BSI. Full ISMS scope covers all client engagements.