Book a scoping callBook a call

How well would your systems survive an attack?

We test your systems the way a real attacker would, following weaknesses to see how far they lead, always inside a scope you approve. When we confirm a finding, you see the evidence in Outer Core and can fix it with the tester who found it.

We test your systems like an attacker would, within an agreed scope, and show you each confirmed finding as we go.

Vetted testers, EU data residency, detailed report and free retest
Live findings
acme-app / web
CriticalWeb App
SQL injection in the login endpoint
Pending Fix
Live findingsacme-app / web
CriticalWeb AppPending Fix
SQL injection in the login endpoint

Confirmed findings appear while the test is running

In a traditional pentest, the findings arrive when the test is already over.

What a tester finds early waits in their notes until the report is written. Your team starts fixing weeks later, from a document, with no one left to ask. And the worst of it: an attacker has those same weeks to find it first.

How it works

Watch it happen

Follow one finding through the whole engagement. Your tester confirms it, shows the evidence, answers questions and returns to verify the fix in the same Outer Core workspace.

Follow one finding from confirmation to verified fix in Outer Core.

Delivery flow
New finding submitted
Critical, Web App Draft
SQL injection in the login endpoint
OP Submitted by a tester, just now
Delivery flow
Finding reported
New finding submitted
Critical, Web App Draft
SQL injection in the login endpoint
OP Submitted by a tester, just now
Triage
SQL injection in the login endpoint
Accept Reject
Reviewed by the lead tester: accepted as valid.
Outer Heaven
ops@outerheaven.ee
now
Critical finding confirmed on your web app
We confirmed a SQL injection on your login endpoint. Full evidence and remediation are in Outer Core.
Delivered ✓
acme/webapp #482
[Critical] SQL injection in login endpoint
security critical outer-core
Synced from Outer Core ✓
Critical, Web App Fixed
SQL injection in the login endpoint
$ retest /api/login
↳ 401 Unauthorized: exploit blocked
Security report ready
All findings closed, audit-ready, 6 of 6 fixed
Download PDF Share with auditor
Step 1 of 6

A tester submits a confirmed vulnerability. It lands as a draft.

Certifications held by the testers who run these engagements.

OSCPOSWEGWAPTeWPTXeCPPTCRTOBurp Suite PractitionerAWS Cloud Security Practitioner
What we test

Test the systems your business depends on

Every engagement is a penetration test. The scope depends on what you are building and what you need us to test. We match the work to a tester with experience on that surface.

Most requested
Web Application

Authentication, access control, injection and business logic across real roles and flows.

AuthAccess controlInjectionLogic
External Network

Internet-facing services, configuration weaknesses, patching gaps and transport security.

Exposed servicesConfigPatchingTLS
API

REST, GraphQL, SOAP and other application APIs, including authorisation, input handling and rate limits.

BOLAMass assignmentRate limits
Also covered, same standard, same depth
Internal Network
Lateral movementPriv-escAD
Cloud
IAMRolesStorage
Source Code
SecretsAuth logicFix review
Mobile
StorageTransportMASVS
Emerging
AI / LLMPrompt injection, tool access, data exposure and the boundaries around model output.
Prompt injectionJailbreaksData leakage
What we test

Test the systems your business depends on

Tell us what you are building and what needs testing. We will match the work to a tester with experience on that surface.

Most requested
Web Application

Authentication, access control, injection and business logic across real roles and flows.

AuthAccess controlInjectionLogic
External Network

Internet-facing services, configuration weaknesses, patching gaps and transport security.

Exposed servicesConfigPatchingTLS
API

REST, GraphQL, SOAP and other application APIs, including authorisation, input handling and rate limits.

BOLAMass assignmentRate limits
Surface 1 of 3
Also covered, same standard, same depth
Internal Network
Lateral movementPriv-escAD
Cloud
IAMRolesStorage
Source Code
SecretsAuth logicFix review
Mobile
StorageTransportMASVS
Emerging
AI / LLM

Prompt injection, tool access, data exposure and the boundaries around model output.

Prompt injectionJailbreaksData leakage
How To Collaborate

Fix it with the person who found it

Ask the tester for context, share the evidence with your engineers and request a retest when the fix is ready. The conversation and status stay with the finding in Outer Core.

Ask the tester questions and request a retest when the fix is ready. Everything stays with the finding.

01
Confirmed

Tester validates the finding with evidence.

02
Pending Fix

Owned by your team, with remediation guidance.

03
Ready to Retest

You patch; we re-verify against the same case.

04
Fixed

Closed and evidenced. Or accepted as known risk.

Talk to the tester directly

Ask the tester who found the issue how to reproduce it, what makes it exploitable and whether your proposed fix addresses the cause.

TesterConfirmed SQLi on the login endpoint. Parameterize the query. Here's the exact payload.
YouPatched on staging. Ready to retest.
Collaborate right in GitHub

A confirmed finding becomes a GitHub issue automatically, with its severity, evidence and remediation guidance. Comments sync both ways. The finding status and final report remain authoritative in Outer Core.

acme/webapp issue #482
[Critical] SQL injection in login endpoint
securitycriticalouter-core
Finding lifecycle
Confirmed

Tester validates the finding with evidence.

Two ways to close it
Talk to the tester directly

No account manager in the middle. Ask the tester who found the issue how to reproduce and fix it, in context, on the finding.

TesterConfirmed SQLi on the login endpoint. Parameterize the query. Here is the exact payload.
YouPatched on staging. Ready to retest.
Collaborate right in GitHub

A confirmed finding becomes a GitHub issue automatically, with its severity, evidence and remediation guidance. Comments sync both ways. The finding status and final report remain authoritative in Outer Core.

acme/webapp issue #482
[Critical] SQL injection in login endpoint
securitycriticalouter-core
How To Track Progress

See what has been fixed

Retest results update the finding record and the dashboard. Your team can see what remains open and what the tester has verified in the tested context.

The chart uses sample data to show how progress can be tracked across an engagement.

Risk trend: a sample engagement
223
Open findings
80
Critical + High open
−86%
Overall risk
0246Critical → 0High → 0InitialRetest 1Retest 2Retest 3ACROSS ENGAGEMENTS OVER TIME →
CriticalHigh
2 recurring findings surfaced and were caught again on retest. Nothing slips between engagements.

See what has been fixed

Retest results update the finding record, so your team can see what remains open and what the tester has verified.

The chart below uses sample engagement data.

Risk trend
223
Open findings
80
Critical + High open
−86%
Overall risk
0246Critical → 0High → 0InitR1R2R3ACROSS ENGAGEMENTS OVER TIME →
CriticalHigh
2 recurring findings surfaced and were caught again on retest. Nothing slips between engagements.
Work with us

There are three ways to work with us

Book a pentest, work with us as a partner or apply to join the tester bench.

You need a pentestFor your own systems
  • Agree the systems, timing and testing rules
  • See confirmed findings and speak with the tester
  • Retest fixes and download the final report
Get a pentest
You sell pentestsFor your clients
  • Refer an opportunity or discuss a reseller model
  • Bring in a vetted delivery team when you need one
  • Keep the client relationship clear
Become a partner
You do pentestsJoin our hackers
  • Work on scopes that match your experience
  • Stay responsible for your findings through retest
  • Use one workflow for evidence and communication
Apply as a tester
Door 1 of 3
Delivery standard

A pentest should leave your team ready to act

Your team can see what was tested, reproduce each confirmed issue and know what to fix next.

Depth
Evidence your team can reproduce.

Each confirmed finding explains the affected system, conditions, proof and demonstrated impact.

Actionable report
Guidance tied to the cause.

Remediation guidance gives engineers a practical place to start and keeps the tester available for questions.

No surprises
A clear engagement record.

The approved scope, methodology, findings and recorded retest results stay together.

Delivery standard

A pentest should leave your team ready to act

Your team can see what was tested, reproduce each confirmed issue and know what to fix next.

Depth
Evidence your team can reproduce.

Each confirmed finding explains the affected system, conditions, proof and demonstrated impact.

Actionable report
Guidance tied to the cause.

Remediation guidance gives engineers a practical place to start and keeps the tester available for questions.

No surprises
A clear engagement record.

The approved scope, methodology, findings and recorded retest results stay together.

Theme 1 of 3
Company

Outer Heaven sets the standard. Outer Core runs every test.

Outer Heaven is the company and brand. Outer Core is its first live venture: the penetration testing practice and platform used for every engagement.

Company

Outer Heaven and Outer Core

Outer Heaven sets the standard. Outer Core is where each penetration test runs.

The venture

The penetration testing practice and delivery platform used for every engagement.

core.outer-heaven.com
Common questions

What teams ask before a pentest

Is this automated or AI scanning?

No. Every engagement is led by a human penetration tester. Tools may help with discovery, testing and evidence collection, but they do not decide what counts as a finding. The tester validates the issue, determines its impact, connects related weaknesses and explains what it means for your system.

How is this different from a bug bounty?

A bug bounty invites researchers to report issues under a standing programme. Our work is a time-bound penetration test with an agreed scope, a responsible tester and a reviewed report.

Where is our data hosted?

All Outer Core data, including user and engagement data, is stored in the EU.

What does the final report include?

The report documents the approved scope, methodology, confirmed findings, evidence and remediation guidance. Your auditor, assessor or customer decides whether it meets their requirement.

How fast can we start?

Timing depends on the scope and the availability of a tester with the right experience. After scoping, we will confirm the testing window in the quote.

What does it cost?

Pricing is based on the systems, depth, timing and access involved. We agree the scope first, then send a quote for approval before testing begins.

Get started

See what an attacker could reach

Tell us what you need tested. We will agree the scope, match the right tester and send a quote before any work begins. Once the test starts, confirmed findings appear live in Outer Core.Tell us what you need tested. We will agree the scope and send a quote before any work begins.

Book a scoping call View a sample report

Scope-based pricing. You approve the quote before testing starts.