Studio Cociu · Google Cloud Partner

Cybersecurity at the level of decision-makers

Penetration testing and security advisory with a signed Letter of Authorization, recognised methodology and reports built for boards. From web applications to critical infrastructure.

OWASP Top 10 PTES methodology NIST SP 800-115 LoA always signed NDA on request

Services
Choose your level of engagement

Every engagement starts with a Letter of Authorization signed by the legal representative, defining IPs, domains and time window. No activity outside the agreed scope.

Starter
€3.500 / progetto
Web Application Assessment
  • 1 domain / web application
  • Full OWASP Top 10
  • Authentication and business-logic testing
  • Technical report + executive summary
  • Delivery in 5–7 days
Get started
Executive
€25.000 / progetto
Full Red Team Engagement
  • Real multi-vector attack simulation
  • Social engineering (only if authorised)
  • Detection and response testing of the internal team
  • Executive report for board / directors
  • Direct presentation to decision-makers
  • Follow-up remediation check · 3–6 weeks duration
Contact us

Methodology
A rigorous approach, not just a scanner

We combine internationally recognised standards with manual verification. Automation finds the noise; human analysis finds what really matters.

Recon & mapping

Enumeration of exposed surfaces, services and technologies. We precisely define what is actually attackable.

OWASP · PTES · NIST

Testing conducted per OWASP Top 10, PTES and NIST SP 800-115: systematic, repeatable and documented coverage.

Controlled exploitation

Vulnerabilities are not just reported: where authorised, real impact is demonstrated without harming the systems.

Two-level reporting

Technical report with evidence and remediation for operators, a clear executive summary for decision-makers.

Process

Initial contact

Definition of scope, objectives and timeline with the company contact.

Letter of Authorization

Signature of the legal representative: authorised IPs, domains and period, put in writing.

Engagement

Assessment within the agreed perimeter. No out-of-scope activity, continuous communication.

Report

Delivery of technical report and executive summary within the agreed deadlines.

Debriefing

Presentation to decision-makers and a prioritised remediation roadmap.


Coming soon · by invitation

AI-powered Security Assessment

We are integrating next-generation models able to reason about source code, finding classes of vulnerabilities that traditional pattern-based scanners miss.

Studio Cociu is in the accreditation process for advanced-access programs in the Anthropic ecosystem, whose presentations it followed closely at Google Cloud Next 2026.

Research published by Anthropic has shown models able to find vulnerabilities that stayed latent for over twenty years in mature software. We bring this approach to professional assessment.

Request early access
AI-native
analysis that reasons about code, not just pattern matching
By invitation
limited early access
Next '26
present at Google Cloud Next 2026
In accreditation
Anthropic advanced-access programs

FAQ
Frequently asked questions

Answers to the questions we are asked most often before an engagement.

What is the Letter of Authorization and why is it mandatory?

It is the document, signed by the organisation's legal representative, that formally authorises the testing activities specifying IP addresses, domains and time window. Without a LoA we start no activity: it is what makes the penetration test legal and traceable.

Which standards and methodologies do you follow?

OWASP Top 10 for web applications, PTES (Penetration Testing Execution Standard) for the overall process and NIST SP 800-115 as a technical reference. Coverage is systematic, repeatable and documented.

Do you operate only on authorised systems?

Always and exclusively. Every activity takes place within the perimeter defined by the LoA. No test is ever conducted on third-party systems or outside the agreed scope.

What do I receive at the end of the assessment?

A technical report with evidence and prioritised remediation guidance, and an executive summary readable by the board. For larger engagements a direct presentation to decision-makers is included.

How long does an engagement last?

It depends on scope: a Web Application Assessment takes 5–7 days, an Infrastructure Assessment 10–15 days, a Full Red Team 3–6 weeks. The precise timeline is agreed in the initial phase.


Agentic payments
Purchasable by AI agents too

The service is exposed via frontier agentic-commerce protocols: an AI agent can discover the catalogue and initiate the engagement autonomously. Every engagement still starts with a scoping retainer and a signed Letter of Authorization.

UCP · Google

Universal Commerce Protocol for Gemini and AI Mode.
/.well-known/ucp

ACP · OpenAI

Agentic Commerce Protocol for ChatGPT and Operator, via Stripe.
/.well-known/acp

x402

Native HTTP 402 payments for agents.
/.well-known/x402

Start the engagement

€500 scoping retainer to start the assessment. Balance after the signed Letter of Authorization and agreed scope. Humans: payment via SumUp. AI agents: payment via Stripe (ACP).


Contact
Start your assessment

Describe your scope and you will get a reply within 24 hours with the proposal and the Letter of Authorization template.