Gabriel Delmelo
Founder & CEO · Security Analyst
5 years as a systems administrator and a Master's degree in Cybersecurity. Founded DELSTRIKE to bring offensive security testing to online stores.
LinkedIn profileOffensive security · E-commerce
Penetration Testing for E-Commerce
Know your vulnerabilities before attackers do. We break into your store the way a real adversary would — under written authorization, with a defined scope, and a report your team can act on the same week.
Fixed price after the scoping call, no surprises.
01 — The problem
Scanner results are incomplete. Logic flaws, authorization bypasses and business logic abuse stay hidden until someone with intent goes looking.
Automated tools check signatures, not intent. Coupon stacking, price tampering and checkout abuse never show up in a scan report.
Without proof of impact, findings sit in a backlog. Every week a flaw stays open is a week someone else can find it.
Chargebacks, refund abuse and account takeovers erode margin quietly. The cost appears in finance long before it appears in IT.
02 — Approach
PTES methodology, authorized, legal-first. Automated tools are where we start, not where we stop: every finding is verified and taken as far as a real attacker would go.
No scan-and-forward. We chain weaknesses together the way an adversary would, and show you exactly how far they lead.
PTES methodology. Eight phases, zero guessing. Every finding comes with severity and reproducible evidence.
Authorized, legal-first, GDPR and NIS2 aligned. Clear rules of engagement before a single request touches your systems.
03 — Compliance
Testing is only useful if it supports the obligations you already have. Every report maps findings to the frameworks your auditors ask about.
Personal data encountered during testing is minimized, never exfiltrated and handled under a data processing agreement. Findings support your Article 32 security obligations.
Regular, documented security testing is part of the risk management measures NIS2 expects. Reports are structured to serve as evidence for your management body.
Assessments cover the payment flow and its surrounding attack surface, and can be scoped to support Requirement 11 penetration testing evidence.
Findings and remediation tracking map to Annex A technical controls, giving your ISMS a clear record of tested and verified safeguards.
All assessments conducted under written authorization.
04 — Methodology
The Penetration Testing Execution Standard, applied end to end. You always know which phase we are in and what comes next.
01
Objectives, targets and rules of engagement, signed.
02
Public footprint, tech stack and third-party exposure.
03
Every endpoint, role and flow your store exposes.
04
Logic, authorization and injection paths ranked by risk.
05
Controlled proof that the flaw is real and reachable.
06
What an attacker could reach, take or change next.
07
Executive summary plus technical detail per finding.
08
Fix guidance and a retest to confirm closure.
05 — Team
Founder & CEO · Security Analyst
5 years as a systems administrator and a Master's degree in Cybersecurity. Founded DELSTRIKE to bring offensive security testing to online stores.
LinkedIn profile06 — Packages
Three scopes, one standard of rigor, each package adding capabilities on top of the previous one.
Fixed quote after the scoping call
Fast Coverage
Comprehensive
Full Realism
07 — Next steps
We write to you to propose a short call to understand your store, platform and goals. We agree on targets, modality and testing window.
You receive a fixed-price proposal and the rules of engagement. Nothing is tested until the authorization is signed.
We run the agreed PTES phases, alert you immediately on critical issues and deliver the report in a live session.
08 — FAQ
Black-box means we start with no prior knowledge, exactly like an outside attacker. Grey-box gives us test accounts or partial documentation so we can reach deeper flows faster. White-box includes source code or architecture access for the most thorough coverage in the time available.
No. We agree on rules of engagement before starting, avoid denial-of-service techniques, and use proof-of-concept payloads that demonstrate impact without damaging data. Production testing windows can be scheduled to suit your traffic.
48 hours of testing for Essentials and 72–96 hours for Professional, followed by the written report. Enterprise timelines are estimated together with you after the scoping call. Critical issues are reported immediately, not at the end.
We stop, notify your designated contact the same day with evidence and an interim mitigation, and agree on how to proceed before continuing.
Yes. Every report includes fix guidance per finding, and we retest remediated issues to confirm they are closed.
Engagements are run under a signed authorization and a data processing agreement, with data minimization by default. Reports are structured to serve as evidence for GDPR Article 32 and NIS2 risk management obligations.
09 — Contact
Leave your email, platform and the package you're interested in. We'll write back to propose a scoping call.
Would you rather write to us directly?contact@delstrike.com