Penetration testing Every system has a heel.
Achilles looks for it before someone else does. Penetration testing and vulnerability research for companies that would rather know where they're exposed than find out afterwards.
Independent research, not partnership
Where we do research
Alongside client engagements, we hunt for vulnerabilities in bug bounty programmes on Intigriti and YesWeHack. We are not partners of either platform: we work there as independent researchers. It's where the method stays sharp, against real systems defended by real teams.
Four kinds of engagement
What we test
They can be combined, but each has its own scope and its own outcome. Every engagement is built around your environment and what worries you.

Application penetration test
We attack the application the way someone who really wants in would: authentication, access control, business logic, data handling. By hand, because scanners don't know what your application is supposed to do, so they can't tell when it does something else.
You get the vulnerabilities we found, each with proof that it can be exploited and guidance on closing it.
Request this test
Network and infrastructure test
We start from whatever is reachable from the internet, or from an ordinary workstation inside the network, and see how far it goes: exposed services, weak configurations, reused credentials, paths to the systems that matter.
You get the attack path step by step, so it is clear which link is worth breaking first.
Request this test
Vulnerability assessment
A broad sweep of everything that is exposed, with findings verified by hand and cleared of false positives. Shallower than a penetration test, wider: useful as a starting point or as a periodic check.
You get a list ordered by real severity, not by the score a tool assigned.
Request this test
Retest
After the fixes we go back to the same spots and retry the same attacks, plus the obvious variants. A patch that blocks the proof but not the cause is the most common case.
You get a verdict for each vulnerability: closed, partial or still open.
Request this testAlways in the same order
How an engagement runs
Five steps. Nothing starts without written authorisation.
Step 1 / 5
Scope
We agree on what gets tested, during which hours and within which limits. It all goes into a signed document before anything is touched.
Step 2 / 5
Reconnaissance
We map the attack surface: what you know is exposed, and what you didn't know was still switched on.
Step 3 / 5
Attack
Manual testing, chained vulnerabilities, concrete proof. If something critical turns up we tell you straight away, without waiting for the report.
Step 4 / 5
Report
Every vulnerability with severity, steps to reproduce and a recommended fix. A summary for those who decide, the detail for those who build.
Step 5 / 5
Retest
Once you have fixed things, we verify. The engagement ends when the problems are closed, not when the PDF is delivered.
The firm
Offensive security is all we do
Achilles is an offensive security firm based in Cuneo, Italy. Every engagement has an agreed scope, a single technical point of contact and a report written by whoever ran the test.
Alongside client engagements, Achilles does independent vulnerability research in the bug bounty programmes of Intigriti and YesWeHack and works with CompTIA-certified skills. It is the same method we bring to companies that want a tailored test.
Cuneo, as it happens, is also the Italian word for wedge: the tool you drive into a crack to open it. That's the job.

- Based in
- Cuneo, Italy
- Platforms
- Intigriti, YesWeHack
- Certifications
- CompTIA
- Working languages
- Italian, English
Frequently asked questions
Before you request a penetration test
What is the difference between a penetration test and a vulnerability assessment?
A vulnerability assessment is a broad sweep: it lists what is exposed and orders it by severity. A penetration test goes deep on a defined scope: it tries to actually exploit vulnerabilities and chain them, to show how far an attacker could get.
Do you need authorisation to run a penetration test?
Yes, always. No test starts without a signed document that sets out what is tested, during which hours and within which limits. Testing a system without the authorisation of whoever is responsible for it is a crime.
Can a penetration test take production systems down?
The risk is handled before we start: hours, limits and techniques to exclude are agreed in the scope. If something critical turns up during the test, we tell you straight away without waiting for the report.
What does a penetration test report contain?
Every vulnerability with its severity, the steps to reproduce it and the recommended fix. It opens with a summary for those who decide; the technical detail is for those who build and run the systems.
Do you check that the problems are closed after the fixes?
Yes, with a retest: we go back to the same spots, retry the same attacks and the obvious variants, and for each vulnerability we state whether it is closed, partial or still open.
Ready?
Tell us what you want tested.
Two lines on what you have and what worries you are enough. We reply with precise questions and then with a quote for a defined scope.
Or write to info@achillessecurity.it