Audit & pentest
At Oxydian, we carry out comprehensive cybersecurity audits and penetration tests (pentests) to identify and fix the vulnerabilities in your systems before they can be exploited.
Whether you are an SME, a mid-sized company or a large enterprise, our expertise guarantees an accurate diagnosis and a concrete action plan.
What is an intrusive audit or pentest?
An intrusive audit is a proactive security assessment involving controlled penetration tests to identify the vulnerabilities and risks of a system, network or application.
Our experts simulate a targeted attack in order to identify potential security flaws that could be exploited by malicious actors.
Objectives
Our approach involves examining your information systems in depth to uncover any vulnerability, whether technical, organisational or user-related.
Drawing on methodical analysis and realistic scenarios, we measure the potential impact of each weakness and prioritise the risks.
Every assessment is tailored to the actual configuration and operation of your infrastructure, providing you with fast, effective solutions to reduce threats and strengthen your security for the long term.
Types of audit
Discover our main types of audit, suited to every environment and security level.
Internal audit
Web application audit
External audit
Architecture audit
Code audit
Configuration audit
Red Team engagement
Physical intrusion
Retest
Our audit and pentest methodology
Oxydian applies a proven approach based on international standards (OWASP, PTES, NIST).
1 – Planning
Defining the objectives and scope of the cybersecurity audit to align the tests with your priorities.
2 – Reconnaissance
Mapping assets and gathering information to identify the attack surface.
3 – Exploration
Manual investigation combined with the innovative tools developed by Oxydian to detect exploitable vulnerabilities.
4 – Exploitation
Controlled attack simulation to validate the presence and impact of the identified flaws, as well as the resilience of the targets.
5 – Report & action plan
Delivery of a report detailing the actions carried out, the identified vulnerabilities ranked by criticality, and personalised recommendations to improve security.
Audit profiles
Depending on your needs, we offer three distinct audit profiles, ranging from real-world testing to full-access analysis.
Black box

The auditor has no prior access to any information, just like an external attacker.
Grey box

The auditor only has access to certain information. This scenario represents the case of a compromised account.
White box

The auditor has full (admin) knowledge in order to carry out an in-depth audit.
Our audit reports
Our audit reports are clear, detailed and actionable, designed for both technical teams and decision-makers. They provide a comprehensive view of the current state of your cybersecurity, with concrete, personalised fixes to make remediation easier.
Contents (around 100 pages):
- Executive summary
- Action plan
- Compromise scenario
- Mapping
- Password analysis
- Vulnerability details and fixes
Frequently asked questions
Why carry out a pentest?
To detect vulnerabilities before an attacker does, to meet regulatory requirements (HDS, ISO 27001, GDPR…), or to reassure your clients and partners about the security of your systems.
How long does an audit take?
From 3 days to 3 weeks, depending on the size of your infrastructure or the scope being audited.
Will the audit disrupt my operations?
No, our tests are designed not to disturb your production environment and to avoid any impact. The most intrusive actions, which could cause disruption, are only carried out with your prior agreement or in a dedicated test environment.
Do you provide support after the audit?
Yes. Our experts remain available to advise you while you fix the flaws, carry out a retest to validate the fixes, or support you in improving your overall security.
Do we have to give you access for the audit?
It depends on the type of audit chosen. In black box, we have no initial access. In grey box, we have limited access. In white box, you provide us with complete technical information.
Audit certificate
At the end of every audit, you receive an official certificate confirming that the audit of your information system has been carried out.
This concise one-page document presents the main findings without disclosing any sensitive data.
It is issued via our secure exchange platform, electronically signed, and its authenticity can be verified at any time through a dedicated online portal.
Book a 30-minute appointment
Enjoy a one-to-one conversation with a cybersecurity expert and gain an outside perspective on the protection of your information system. Together, we will identify your challenges, your priorities and the first areas for improvement.
In 30 minutes, discover our methodology, our deliverables, our advanced analysis tools and benefit from personalised advice from one of our experts.