Overview
Elite Offensive Security
Cyrex delivers penetration testing through Renewed Pair Hacking, combining senior security engineers with proprietary AI agents to uncover vulnerabilities across applications.
Cyrex Penetration Testing - AI-Augmented Offensive Security
Cyrex delivers penetration testing for organizations operating complex digital products and infrastructure on AWS and beyond. Each engagement is performed through the Renewed Pair Hacking methodology, where senior security engineers work alongside proprietary AI agents that automate reconnaissance, generate attack paths, and expand test coverage - while expert human judgment drives exploitation, validation, and strategic analysis.
What We Test
Cyrex assessments cover modern technology stacks including:
- Web applications and SaaS platforms - authentication flows, session management, business logic, and multi-tenant isolation
- APIs and microservices - REST, GraphQL, gRPC, and custom protocols
- AWS cloud environments - Amazon EC2, AWS Lambda, Amazon EKS, Amazon S3, AWS IAM policies, VPC configurations, and serverless architectures
- Network infrastructure - internal and external perimeter testing, segmentation validation
- Web3 ecosystems - smart contract exploitation, DeFi protocol analysis, bridge vulnerabilities
- Online multiplayer games - anti-cheat bypass testing, real-time protocol fuzzing, game economy manipulation
How an Engagement Works
A typical Cyrex engagement follows a structured lifecycle:
- Scoping call - Cyrex conducts a discovery session to understand your architecture, threat model, and compliance requirements
- Engagement planning - Testing windows, access provisioning, and rules of engagement are agreed upon
- Offensive testing - Senior engineers and AI agents execute coordinated attacks across the defined scope
- Vulnerability validation - Every finding is manually verified to eliminate false positives
- Reporting - A detailed technical report with executive summary, finding severity ratings, and step-by-step remediation guidance is delivered
- Advisory and retesting - Post-engagement consulting, remediation support, and verification testing confirm fixes are effective
Engagements typically run two to four weeks depending on scope complexity.
What You Receive
- Detailed technical findings report with proof-of-concept exploits
- Executive summary suitable for board-level stakeholders
- Remediation roadmap prioritized by risk severity
- Post-engagement consulting session
- Verification retest to confirm remediation effectiveness
Use Case: SaaS Platform Preparing for Compliance
A SaaS company preparing for SOC 2 or ISO 27001 certification engages Cyrex to validate their security posture before the audit. Cyrex scopes the assessment around the platform's AWS infrastructure (EC2, Lambda, S3, IAM), customer-facing APIs, and authentication mechanisms. The engagement identifies exploitable vulnerabilities and provides a remediation roadmap that directly maps to compliance control requirements, enabling the customer to close gaps before their audit window.
Prerequisites and Buyer Responsibilities
To begin an engagement, buyers must provide:
- Written authorization for testing (scope agreement and rules of engagement)
- Environment access credentials or test accounts as applicable
- Architecture documentation or diagrams for scoped systems
- A designated point of contact for coordination during testing
Scope Boundaries
Standard engagements do not include physical security testing, social engineering campaigns, or denial-of-service simulation unless explicitly scoped and authorized.
Data Protection
All engagement data - including credentials, architecture diagrams, findings, and reports - is encrypted in transit and at rest. Cyrex follows strict data retention policies with defined deletion timelines post-engagement. Non-disclosure agreements are executed before any sensitive information is exchanged.
Get Started
Contact Cyrex through AWS Marketplace to schedule a free scoping call and receive a tailored proposal for your environment.
Highlights
- Penetration testing delivered through Renewed Pair Hacking, combining senior security engineers with proprietary AI agents for deeper and more consistent coverage.
- Tailored security assessments across applications, APIs, SaaS platforms, cloud environments, networks, custom protocols, Web3, and online multiplayer games.
- End-to-end support from scoping and offensive testing to vulnerability validation, reporting, remediation guidance, consulting, and strategic security advisory.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
Cyrex provides dedicated support throughout the full penetration testing engagement lifecycle.
Engagement Coordination
A designated Cyrex project lead is assigned to each engagement to manage scheduling, access provisioning, and communication. Buyers receive a single point of contact from scoping through final report delivery.
During Active Testing
Critical and high-severity findings discovered during testing are communicated to the buyer's designated contact as they are validated, rather than held until the final report. Testing window adjustments and scope clarifications are handled directly with your project lead.
Post-Engagement Support
- Report clarification and walkthrough sessions
- Remediation guidance and consulting
- Verification retesting to confirm fixes
- Strategic security advisory
Buyer Responsibilities
To ensure smooth engagement delivery, buyers should provide:
- Written testing authorization
- Environment access or test accounts
- A designated internal point of contact
How to Reach Us
Customers can contact the Cyrex team through AWS Marketplace for scoping, coordination, testing updates, and post-assessment support or a meeting can immediately be booked via https://cyrex.tech/contact
Data Handling
All engagement data is encrypted in transit and at rest. Non-disclosure agreements are executed before sensitive information is exchanged, and defined retention and deletion policies apply to all engagement artifacts.