Security for POS, self-checkout, digital scales, e-commerce, loyalty programs and TEF integrations.
Why now
Supermarkets operate on thin margins and high volume — a single POS outage costs millions per hour. ERP ransomware, digital scale fraud, loyalty program manipulation, customer base leaks. Five POS terminals offline on a busy Friday = operational chaos.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Price manipulation, cancellation fraud, card capture and pinpad tampering.
Weighing bypass, barcode fraud, verification camera integrity.
Tare manipulation, weighing fraud, abuse of per-kg promotions.
Point manipulation, base leak, redemption fraud and subscription club.
Cart, coupon, payment, delivery — APIs, webhooks and anti-fraud.
SAP, Linx, supplier security, ransomware readiness and backup integrity.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Sector prioritized in our expansion strategy across southern Brazil and Italy.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. Intrusive tests run in mirror environments. Only final validations touch production in agreed windows.
Yes. We audit firmware, POS integration and weighing fraud by product code.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.