Offensive security in e-commerce, marketplaces, POS, omnichannel and loyalty platforms.
Why now
Digital retail is industrial-scale fraud. ATO, chargeback, catalog scraping, coupon abuse, inventory manipulation, free-shipping fraud — every vector that escapes is margin evaporating from EBITDA.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Price, coupon, shipping manipulation, payment fraud.
Seller onboarding, payout fraud, review manipulation.
Storefront, acquirer integration, cash drop, replenishment.
ATO, points abuse, redemption fraud.
Click & collect, ship from store, cross-channel return/exchange.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Large-scale e-commerce operations.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. ASV scan and penetration test per PCI-DSS 4.0, requirement 11.4.
Yes. Seller onboarding, payout fraud, catalog and review manipulation.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.