Services
Four fronts, one way of working.
We carry out manual exploitation with verifiable evidence for every finding, delivering reports technical teams can act on without interpretation. The scope, the rules of engagement and the testing window are set transparently and in writing before any activity begins.
Offensive security
Manual pentesting against the surface you actually expose. Real exploitation and a reproducible proof of concept for every finding, not a list of scanner output.
What we cover
Web applications
Authentication, access control, business logic and injections. Coverage guided by the OWASP Top 10 and OWASP ASVS, with chained exploitation wherever it exists.
API
REST, GraphQL and SOAP. Object- and function-level authorization, excessive data exposure, rate-limiting abuse. Reference: OWASP API Security Top 10.
Mobile
Android and iOS. Insecure local storage, certificate pinning, anti-tampering protections and the backend sitting behind the app.
Cloud
AWS, Azure and GCP. IAM review and privilege escalation, exposed buckets and storage, poorly segmented networks and secrets leaked in configuration.
AI and LLM
Direct and indirect prompt injection, system prompt leakage, RAG context poisoning and tool or agent abuse. Reference: OWASP Top 10 for LLM Applications.
Code analysis
Reviewing the application from the inside and from the outside. Every automated alert is manually validated before it reaches the report: without triage, a SAST run is mostly noise.
What we cover
SAST
Static analysis over source code. Catches insecure patterns and tainted data flows before deployment, including code no dynamic test ever reaches.
DAST
Dynamic analysis against the running application. Finds what only shows up live: environment configuration, sessions and runtime behaviour.
MAST
Mobile-specific analysis, static and dynamic, over the binary and the traffic. Reference: OWASP MASVS and MASTG.
Banking core
Assessment of financial platforms, where failure is not a data leak but an altered transaction. The team brings prior experience across Mexican SOFIPOs, insurers and banks. Always performed under an agreed window and signed rules of engagement.
What we cover
Core platform
Integrity of transactional logic, dual-control checks, segregation of duties and traceability of sensitive operations.
Interfaces and messaging
Integration channels and financial messaging (ISO 8583, ISO 20022, SWIFT): field validation, replay, amount tampering and idempotency control.
Channels and perimeter
Online banking, the mobile app and the APIs behind them, along with the network segmentation separating the core from the rest of the organization.
PCI DSS analysis
Technical work on the cardholder data environment (CDE) so the formal assessment arrives without surprises.
What we cover
Gap analysis
Review of the CDE against the PCI DSS v4.0 requirements, with the real distance to compliance and a prioritized remediation plan.
PCI-scoped pentest
The internal and external penetration test required by Requirement 11.4, with methodology, scope and evidence documented the way the standard asks for.
Segmentation testing
Verification that segmentation controls genuinely isolate the CDE, per Requirements 11.4.5 and 11.4.6, to support scope reduction.
Argus RK is neither a QSA nor an ASV. We perform the technical work and the penetration testing the standard requires, and prepare the evidence; the formal assessment and the signing of the RoC or SAQ belong to an accredited QSA, and the quarterly external scan to an ASV.
Does any of this match what you need?
Tell us the scope and we send back a technical proposal in under 48 hours.