Skip to main content
Erik Nilsen

Free penetration test

A written report with findings ranked by severity, concrete recommendations, and one retest once the fixes are in place. Web, cloud, and code, with AI as an active part of the toolkit for broader coverage and more creative findings.

Building a portfolio in offensive security. You get the full deliverable. Want to see the terms before reaching out? Generate a complete Statement of Work right in your browser.

What clients say

Translated from Norwegian.

Carried out a security test of our website and found a vulnerable point we weren't aware of. The hole was patched quickly, and we got a clear explanation of what was wrong and how it was fixed.
Wiktor, AutoHobby AS
As a web designer, the security of the sites I build is something I genuinely take seriously. So I was very surprised and alarmed when Erik discovered that my own website was an easy target for spoofing. I'm incredibly grateful to have been made aware of this so I can do something about the flaw, and I'd strongly recommend other businesses get their websites checked too.
Web designer (wishes to remain anonymous)Read the full story (Norwegian) →
Erik has helped increase security at ReAI, which means an incredible amount to us as a provider of accounting software.
Greg, ReAI AS
Erik tested our systems and found holes we weren't aware of. With his help, we were able to effectively close these before any potential 'black hats' could help themselves to sensitive data.
Client (wishes to remain anonymous)

What I offer

Web applications

OWASP Top 10, authentication, authorization, API testing.

Network and cloud

Configuration, exposed services, Azure/M365 tenants.

Code review

Manual and automated review of critical components.

OSINT, social engineering, and red-team-oriented engagements are also possible, provided they're explicitly agreed and authorized in a signed SoW.

How I test

When the scope includes a web app or service, I run an unauthenticated baseline by default: RCE attempts, auth bypass, OWASP Top 10 checks, and known CVEs in the components I see. This happens regardless of what else we agree on.

Authenticated testing

Want the inside tested too? Then I'll need logins, ideally a dedicated test account with normal-user privileges (not admin) so we avoid touching real data. That lets me test authorization, IDOR, user separation, and what's behind the login.

Scheduled phishing emails

I can queue emails for agreed times. Got an important board meeting, a launch, or another event you want to test around? Let me know, and the phishing emails will land at the most credible possible time.

AI as an active part of the toolkit

I use AI throughout the test to suggest attack vectors, combine information, and be creative in ways a single person rarely is. AI gets full pentest capacity within the agreed scope (never outside it). The result is broader coverage and more creative findings than purely manual testing.

The AI is not trained on your data, and I only share what's needed for the specific step at hand, never entire datasets, customer lists, or PII. Sensitive steps can, by agreement, be run exclusively against local models on my own machine.

What you get

  • Written report (PDF).
  • Findings ranked by severity.
  • Recommended remediation per finding.
  • One retest once the fixes are in place.

How it works

  1. 1

    Request

    You fill out the form with your desired scope and contact info.

  2. 2

    Clarification

    I reply by email with clarifying questions about scope and ownership.

  3. 3

    SoW + authorization

    I draft the SoW and written authorization, signed by an authorized person at the company.

  4. 4

    Testing

    Carried out within the agreed window, strictly within the signed scope, with clear logging.

  5. 5

    Report

    Written report (PDF) with findings ranked by severity, concrete recommendations, and one retest.

My commitments

  • I test nothing until a signed SoW and written authorization are in place.
  • I stay strictly within the agreed scope. If I'm in doubt, I ask you before I act.
  • You can ask me to stop at any time, and I stop immediately.
  • You get a written report with all findings. Nothing is shared with third parties.

What I appreciate

  • A quote or reference I can share when building my portfolio.
  • The option to write a blog post about the engagement, with no PII or company-sensitive info, and you review it before publication.

Request a pentest

You'll get an email confirmation, and I'll be in touch within 1-2 business days. The more detail you give upfront, the faster the SoW gets drafted.