we break in,write it down,and stay till it's fixed
Penetration testing, red teaming and security advisory for organisations that would rather find out from us. Every fix we recommend gets retested, at no extra cost, within ninety days.
- 480+
- engagements
- 37
- cves published
- 90d
- retest window
Most reports tell you what a scanner noticed. Ours tell you what a person did, in your system, and what happened next.
devwalls is thirty-one people across Abuja and London. We run penetration tests, red team operations, cloud reviews and embedded application security work. We publish our research under our own names, we grade findings on whether they are exploitable rather than on whether a tool flagged them, and we retest every fix we recommend without charging for it again.
Thirty-one people. Two offices. Every report signed by the person who wrote it.
- 01
penetration testing
Time-boxed, scoped testing of a system you already have, graded against exploitability rather than a scanner's opinion.
5–15 - 02
red teaming
An objective-led simulation of a real adversary, run against your detection and response rather than against a checklist.
4–10 - 03
cloud security review
A read of your AWS, Azure or GCP estate as an attacker reads it: identity first, blast radius second, compliance a distant third.
10–20 - 04
application security
Design review, threat modelling and code-level testing embedded with the team building the thing.
Retained,
- 01
Scope
1 week before startWe argue about scope until it is narrow and written down. A vague scope produces a vague report. This is a call with the people who own the systems, not a form.
- 02
Recon
Days 1–3We build a picture of your attack surface from the outside, the way someone targeting you would. Frequently we find assets you had forgotten you owned. That list alone has ended engagements early.
- 03
Test
The bulk of the engagementHumans in your system, chaining findings rather than listing them. Anything critical is called the same day. You have a shared channel with the testers throughout.
- 04
Report
Within 5 days of test endOne document, two audiences. Engineers get reproduction steps and remediation notes. The board gets a page in plain English. Neither is a template with your logo dropped in.
- 05
Fix
Your timelineWe stay available while you fix. Most clients use us as a second pair of eyes on the patch. This is included, not billed.
- 06
Retest
Within 90 daysWe test every fix and update the report. A finding is only closed when we have failed to exploit it again. Included in the original price.
tell us what you would least like us to reach
Scoping is a conversation with the people who own the systems, not a form. Twenty minutes is usually enough to tell whether we are the right practice for the problem.
