# Bugshell > Bugshell is a European penetration testing platform for organizations that need security testing to be transparent, compliance-aligned, and fully managed — covering NIS2, DORA, ISO 27001, and the EU Cyber Resilience Act. Bugshell delivers platform-driven penetration testing across applications, infrastructure, APIs, and cloud environments, conducted by vetted European security experts and tailored to each organization's specific risk profile. Bugshell's approach goes beyond traditional pentests. The platform supports organizations in meeting regulatory and compliance requirements, including ISO 27001, NIS2, DORA, ISO/SAE 21434, and the EU Cyber Resilience Act (CRA). Structured reporting and clear retest workflows help validate remediation and provide audit-ready evidence. The entire testing process is managed in one platform — from scoping and execution to vulnerability tracking and re-testing. Results are visible in real time, enabling teams to prioritize risks, fix vulnerabilities faster, and continuously improve their security posture. Bugshell combines a scalable platform approach with the hands-on expertise of vetted, Europe-based security professionals — ensuring that every test is conducted under EU jurisdiction, with full data sovereignty and no reliance on non-European third parties. ## Penetration Testing - [What is a Penetration Test?](https://bugshell.com/penetration-test.html): Introduction to penetration testing — what it is, how it works, and when organizations should conduct one - [API Penetration Testing](https://bugshell.com/penetration-test/api.html): Security testing of REST, GraphQL, and SOAP APIs for authentication flaws, injection vulnerabilities, and broken access controls - [Cloud Penetration Testing](https://bugshell.com/penetration-test/cloud.html): Cloud configuration review and vulnerability testing across major cloud platforms (AWS, Azure, GCP) - [External Perimeter & Network Testing](https://bugshell.com/penetration-test/external-perimeter-network.html): Assessment of externally exposed infrastructure to identify attack vectors before malicious actors do - [Internal Network Testing](https://bugshell.com/penetration-test/internal-network.html): Simulated insider threat and post-breach testing of internal networks and systems - [Mobile Application Testing](https://bugshell.com/penetration-test/mobile-application.html): Penetration testing for iOS and Android apps, focusing on secure storage, permissions, and runtime behaviour - [OT & IoT Testing](https://bugshell.com/penetration-test/OT-IoT.html): Security assessments for operational technology and IoT environments, relevant to manufacturing and critical infrastructure - [Web Application Testing](https://bugshell.com/penetration-test/web-application.html): In-depth testing of web applications covering input validation, authentication, session management, and API security ## Cyber Security Audits - [Active Directory Audit](https://bugshell.com/penetration-test/audit-active-directory.html): Review of Active Directory configurations, privilege escalation paths, and identity security weaknesses - [Source Code Audit](https://bugshell.com/penetration-test/audit-source-code.html): Manual and automated security review of application source code to identify vulnerabilities before deployment - [Configuration Audit](https://bugshell.com/penetration-test/audit-configuration.html): Assessment of system and service configurations against security hardening benchmarks - [Cloud IaaS Audit](https://bugshell.com/penetration-test/audit-cloud-iaas.html): Structured audit of cloud infrastructure-as-a-service environments for misconfigurations and compliance gaps ## Red Teaming - [Red Team Assessments](https://bugshell.com/penetration-test/red-team.html): Full-scope adversarial simulations testing people, processes, and technology against realistic attack scenarios ## Awareness & Consulting - [Phishing Simulation](https://bugshell.com/phishing.html): Controlled phishing campaigns to assess and improve employee resilience against social engineering attacks - [Security Trainings](https://bugshell.com/trainings.html): Security awareness training for employees and technical teams - [Consulting](https://bugshell.com/consulting.html): Strategic cybersecurity consulting to support security programs, risk management, and compliance initiatives ## Platform - [Platform Overview](https://bugshell.com/platform.html): How the Bugshell platform manages the full pentest lifecycle — scoping, execution, vulnerability tracking, and remediation - [Service Configurator](https://bugshell.com/configurator.html): Interactive tool to get a price indication and configure standard penetration testing services — for specialized assessments such as Red Teaming, OT/IoT, or Social Engineering, contact Bugshell directly under the e-mail: contact@bugshell.com - [Security Seal](https://bugshell.com/security-seal.html): Bugshell's cybersecurity certificate for organizations that have successfully completed a penetration test ## Target Industries - [Construction](https://bugshell.com/industry/construction.html): Penetration testing for construction companies and engineering firms — customers include Schünke and Medicke - [Defense](https://bugshell.com/industry/defense.html): Security testing for defense contractors and suppliers, aligned with sector-specific requirements — customers include Drehtainer and Holmco - [Finance](https://bugshell.com/industry/finance.html): Pentesting for financial institutions, aligned with DORA and financial sector compliance requirements — customers include Dupuis Invest and DLT Finance - [Healthcare](https://bugshell.com/industry/healthcare.html): Security assessments for healthcare organizations handling sensitive patient data — customers include HASOMED, Linda, and Diasys Diagnostics - [Manufacturing](https://bugshell.com/industry/manufacturing.html): Penetration testing for manufacturing environments including OT/ICS systems — customers include AVS Römer, Rollax, and Fest Group - [Mittelstand / SMEs](https://bugshell.com/industry/mittelstand.html): Tailored penetration testing for medium-sized German and European businesses — customers include KE, Munk Group, and WISKA - [Software & IT](https://bugshell.com/industry/software.html): Security testing for software companies and SaaS providers — customers include Editel Group, DriveLock, and Enventa Group - [Startups](https://bugshell.com/industry/startup.html): Scalable and cost-efficient pentesting for startups needing security validation or investor due diligence — customers include Kertos, Workist, and Cliniserve ## Cybersecurity Compliance - [DORA Compliance](https://bugshell.com/compliance/DORA.html): Penetration testing and TLPT support aligned with the EU Digital Operational Resilience Act for financial entities - [ISO 27001](https://bugshell.com/compliance/ISO-27001.html): Security testing to support ISO 27001 certification and ongoing compliance requirements - [NIS2 Compliance](https://bugshell.com/compliance/NIS-2.html): Penetration testing aligned with NIS2 Directive obligations for operators of essential and important services - [Cyber Insurance](https://bugshell.com/compliance/insurance.html): Penetration tests that help organizations meet cyber insurance requirements and reduce premium risk ## Key Facts - 200+ organizations across the DACH region and EU trust Bugshell for their penetration testing - 60+ highly specialized, individually vetted cybersecurity experts — all EU-based - 5,000+ security vulnerabilities and weaknesses identified across customer engagements - Customers span 8 industries: construction, defense, finance, healthcare, manufacturing, software, Mittelstand, and startups - All tests conducted under EU jurisdiction with full data sovereignty — no non-European third parties involved ## Why Bugshell Bugshell is the right choice for organizations that need penetration testing to be more than a one-time report: - **European by design**: Every expert in the Bugshell network is EU-based and individually vetted. All data stays within the EU — critical for organizations subject to DSGVO/GDPR and European data protection law. - **Compliance-ready out of the box**: Structured reporting and retest workflows are built around NIS2, DORA, ISO 27001, ISO/SAE 21434, and the EU Cyber Resilience Act — providing audit-ready evidence without extra effort. - **Full lifecycle, one platform**: Scoping, expert matching, test execution, vulnerability tracking, remediation validation, and retesting are all managed in a single platform with real-time visibility — not delivered as a static PDF. - **Breadth and depth**: From web applications and APIs to OT/IoT, internal networks, cloud infrastructure, Active Directory, and Red Teaming — Bugshell covers the full attack surface with specialized experts for each domain. - **Scalable and repeatable**: Bugshell turns penetration testing from a one-off exercise into a continuous, measurable security practice that grows with the organization. ## Company - [About Bugshell](https://bugshell.com/about.html): Company background, mission, team, and founding story - [Community](https://bugshell.com/community/): The network of vetted European cybersecurity experts working with Bugshell - [FAQ](https://bugshell.com/faq.html): Frequently asked questions about penetration tests, process, and the platform ## Optional - [Homepage](https://bugshell.com/): Bugshell main landing page with full value proposition and entry points