7ASecurityWhat ‘Quality Pentests’ Really Mean: 7ASecurity Interviewed by OWASP Executive Director Andrew van der Stock ▶ Need a high-quality pentest or secure code audit? Request a free consultation: 7asecurity.com/#contact
This short clip explains how 7ASecurity audits work—introduced by OWASP Executive Director Andrew van der Stock. Abraham Aranguren (Managing Director, 7ASecurity) covers what “quality” looks like in practice: manual, researcher-led testing (not tool output), interim findings via a dedicated communication channel, actionable reporting with clear replication steps and mitigation guidance, and free fix verification so issues are actually resolved.
7ASecurity is ISO 27001 and SOC 2 certified and an OWASP Platinum Corporate Supporter.
CHAPTERS 00:00 OWASP Executive Director intro 00:28 What 7ASecurity does + certifications 01:03 Trusted by open-source and media organizations 02:16 Public reports and open-source audit work 02:46 What a “real” report includes (validated findings, replication steps, remediation) 04:15 Dedicated comms channel + interim findings during the audit 05:42 Free fix verification + quality guarantee 06:12 Closing
ABOUT 7ASECURITY 7ASecurity is an ISO27001 and SOC2 certified cybersecurity consultancy and OWASP Platinum Supporter specializing in manual, high-quality penetration tests and secure code audits. Trusted since 2011 by the Linux Foundation, Mozilla Foundation, Tor Project, The Guardian, and many others (7asecurity.com/publications). Every engagement is tailored to the client priorities and threat model, and guided through a dedicated channel from scoping to free fix verification. With researcher-led testing that outperforms automation, 7ASecurity consistently uncovers vulnerabilities others miss — delivering real results with proof and replication steps, clear guidance, and measurable security improvements that stand up to real-world threats.
How 7ASecurity Audits Work: Interim Findings + Free Fix Verification (OWASP Director Intro)7ASecurity2026-01-22 | What ‘Quality Pentests’ Really Mean: 7ASecurity Interviewed by OWASP Executive Director Andrew van der Stock ▶ Need a high-quality pentest or secure code audit? Request a free consultation: 7asecurity.com/#contact
This short clip explains how 7ASecurity audits work—introduced by OWASP Executive Director Andrew van der Stock. Abraham Aranguren (Managing Director, 7ASecurity) covers what “quality” looks like in practice: manual, researcher-led testing (not tool output), interim findings via a dedicated communication channel, actionable reporting with clear replication steps and mitigation guidance, and free fix verification so issues are actually resolved.
7ASecurity is ISO 27001 and SOC 2 certified and an OWASP Platinum Corporate Supporter.
CHAPTERS 00:00 OWASP Executive Director intro 00:28 What 7ASecurity does + certifications 01:03 Trusted by open-source and media organizations 02:16 Public reports and open-source audit work 02:46 What a “real” report includes (validated findings, replication steps, remediation) 04:15 Dedicated comms channel + interim findings during the audit 05:42 Free fix verification + quality guarantee 06:12 Closing
ABOUT 7ASECURITY 7ASecurity is an ISO27001 and SOC2 certified cybersecurity consultancy and OWASP Platinum Supporter specializing in manual, high-quality penetration tests and secure code audits. Trusted since 2011 by the Linux Foundation, Mozilla Foundation, Tor Project, The Guardian, and many others (7asecurity.com/publications). Every engagement is tailored to the client priorities and threat model, and guided through a dedicated channel from scoping to free fix verification. With researcher-led testing that outperforms automation, 7ASecurity consistently uncovers vulnerabilities others miss — delivering real results with proof and replication steps, clear guidance, and measurable security improvements that stand up to real-world threats.
#OWASP #AppSec #PenTest #CodeAudit #CyberSecurity #SecureCodeReview7ASecurity Interviewed by OWASP Executive Director Andrew van der Stock (Full Interview)7ASecurity2026-01-18 | What ‘Quality Pentests’ Really Mean: 7ASecurity Interviewed by OWASP Executive Director Andrew van der Stock ▶ Need a high-quality pentest or secure code audit? Request a free consultation: 7asecurity.com/#contact
In this full interview, OWASP Executive Director Andrew van der Stock speaks with Abraham Aranguren (Managing Director, 7ASecurity) about what “high-quality” security testing really looks like: threat-model driven scoping, researcher-led testing, actionable reporting with clear replication steps and mitigation guidance, and free fix verification.
KEY TOPICS COVERED - Manual pentesting vs. checkbox/automated audits - Tailoring scope to a client’s threat model and priorities - Dedicated comms channel during the engagement - Free fix verification + quality standards - OWASP resources used in real remediation guidance (Cheat Sheets, Testing Guide, ASVS) - Open-source security audits and transparency - AI tooling as augmentation (validate before you report)
CHAPTERS 0:00 OWASP Intro 0:35 What 7ASecurity does (pentests, code audits, AI testing, cloud, etc.) 1:11 Public pentest reports & open-source work 5:16 Why communication during a pentest matters 7:06 Free fix verification + quality guarantee 8:54 OWASP OWTF and balancing automation with human validation 18:52 AI in security work (augment, don’t replace) 34:17 Why repeated pentesting reduces severity over time 36:11 Business logic & authorization flaws 37:35 Career advice for new pentesters 47:33 Wrap-up + OWASP 25th anniversary
ABOUT 7ASECURITY 7ASecurity is an ISO27001 and SOC2 certified cybersecurity consultancy and OWASP Platinum Supporter specializing in manual, high-quality penetration tests and secure code audits. Trusted since 2011 by the Linux Foundation, Mozilla Foundation, Tor Project, The Guardian, and many others (7asecurity.com/publications). Every engagement is tailored to the client priorities and threat model, and guided through a dedicated channel from scoping to free fix verification. With researcher-led testing that outperforms automation, 7ASecurity consistently uncovers vulnerabilities others miss — delivering real results with proof and replication steps, clear guidance, and measurable security improvements that stand up to real-world threats.
#OWASP #AppSec #PenTest #CodeAudit #CyberSecurity #SecureCodeReviewWhy do you need a pentest?7ASecurity2024-01-29 | Video presentation on our recent appearance at The Security Repo podcast, with interesting points and comments from the hosts: Mackenzie Jackson and Dwayne McDaniel: 🛡️ Discover 14 compelling reasons why opting for a manual pentest performed by humans is indispensable in safeguarding your digital assets, as well as other interesting topics.
Help the channel grow with a Like, Comment, & Subscribe!LeaveHomeSafe 3.3.0 Retest 2022-07-29: Part 03 - COVID Status Access via Auth Bypass (High)7ASecurity2022-07-29 | LeaveHomeSafe 3.3.0 Retest 2022-07-29: Part 03 - LHS-01-008 WP1 COVID Status Access via Auth Bypass (High)
This video series introduces the app "LeaveHomeSafe", the privacy and security concerns surrounding it and the Audit performed by 7ASecurity on behalf of Hong Kong Democracy Council (HKDC) & Open Technology Fund (OTF).
Hong Kong Democracy Council (HKDC) - hkdc.us Open Technology Fund - https://www.opentech.fund/news/7asecurity-otf-red-team-lab-partner-completes-blackbox-pentest-and-privacy-audit-of-leavehomesafe-app/
Hong Kong government's response - https://www.info.gov.hk/gia/general/202207/28/P2022072800632.htm -------------------------------------------------------------------------------------------------------------------------- These issues are true, try them on your own to confirm :)
This video series introduces the app "LeaveHomeSafe", the privacy and security concerns surrounding it and the Audit performed by 7ASecurity on behalf of Hong Kong Democracy Council (HKDC) & Open Technology Fund (OTF).
Hong Kong Democracy Council (HKDC) - hkdc.us Open Technology Fund - https://www.opentech.fund/news/7asecurity-otf-red-team-lab-partner-completes-blackbox-pentest-and-privacy-audit-of-leavehomesafe-app/
Hong Kong government's response - https://www.info.gov.hk/gia/general/202207/28/P2022072800632.htm -------------------------------------------------------------------------------------------------------------------------- These issues are true, try them on your own to confirm :)
Part 1 of this video series introduces the app "LeaveHomeSafe", the privacy and security concerns surrounding it and the Audit performed by 7ASecurity on behalf of Hong Kong Democracy Council (HKDC) & Open Technology Fund (OTF).
Hong Kong Democracy Council (HKDC) - hkdc.us Open Technology Fund - https://www.opentech.fund/news/7asecurity-otf-red-team-lab-partner-completes-blackbox-pentest-and-privacy-audit-of-leavehomesafe-app/
Hong Kong government's response - https://www.info.gov.hk/gia/general/202207/28/P2022072800632.htm -------------------------------------------------------------------------------------------------------------------------- These issues are true, try them on your own to confirm :)
Get a Free taste of 7ASecurity workshops here: 7asecurity.com/free Check out our self-paced courses: store.7asecurity.com/discount/YOUTUBE Follow us on Twitter: twitter.com/7aSecurityHow to find your personal discount and referral link7ASecurity2021-01-21 | This video explains how to find and use your personal discount code code from our training portal.
I hope this helps, as we got some questions about this :)Cyber4All Webinar: Hacking Web apps with RCE and Prototype Pollution7ASecurity2020-12-09 | Email admin@7asecurity.com for free access to all apps and slides covered in this webinar, practice these exercises at your own pace.
Get 25% off any course: store.7asecurity.com/discount/NY25Practical Mobile app attacks by Example Workshop - OWASP Czech Day7ASecurity2020-12-02 | For full access to workshop materials: Vulnerable apps, slides, recording and future updates, please email admin@7asecurity.com.
Check out our self-paced courses: store.7asecurity.com/discount/YOUTUBEHacking Modern Desktop apps with XSS and RCE Workshop7ASecurity2020-11-17 | Email admin@7asecurity.com for lifetime access to all apps used in this workshop, slides, recording and more.
Interested in our courses? Use this discount: store.7asecurity.com/discount/YOUTUBEHacking Android, iOS and IoT apps by Example7ASecurity2020-06-03 | Training Teaser video for one of our courses: Hacking Android, iOS and IoT apps by Example
For other locations, please see: 7asecurity.com/training#publicHacking Modern Web & Desktop apps: Master the Future of Attack Vectors7ASecurity2020-03-02 | Training Teaser video for one of our courses: Hacking Modern Web & Desktop apps: Master the Future of Attack Vectors