PayaAudit · Pentesting for brokers

Your broker stack is a target. Your last pentest only looked at your website.

PayaAudit by Paya Labs is on-demand, manual penetration testing built for Forex/CFD brokers — senior security engineers who test your Trader's Room, CRM, PSP integrations, and the servers your MT4/MT5 or cTrader platform runs on, not just your marketing site.

· Manual, human-led testing · On demand, no retainers · Fixed scope, fixed quote · Retest included
◆ PayaAudit Portal — every finding we report, tracked from open to verified fixed Severity · Evidence · Remediation · Retest
◆ The problem

The broker attack surface nobody is testing.

Most brokers run a stack that generic security firms never look past the front page of.

01 · Trading servers

Your servers are exposed by design.

The MT4/MT5 or cTrader servers behind your platform must be reachable by thousands of client terminals. One forgotten admin port, one weak gateway credential, one exposed management interface — and an attacker isn't defacing your website, they're pulling account data or moving money.

02 · Trader's Room

Your Trader's Room holds everything an attacker wants.

Client balances, withdrawal flows, KYC documents — passports, proof of address, banking details. A single IDOR or broken access control in the client portal turns into fraudulent withdrawals and a reportable data breach in the same afternoon.

03 · CRM & PSPs

Your CRM and PSP integrations are the quiet back door.

Broker CRMs concentrate every lead, every client record, every deposit. Payment integrations pass sensitive data and callbacks between systems built by different vendors. These seams are exactly where attackers live — and exactly where a website-only scan never looks.

04 · Regulation

And the regulatory floor just moved.

DORA is now in force across the EU, and it explicitly expects financial entities to test their digital resilience — penetration testing included. CySEC-regulated brokers are being asked harder questions about ICT risk than ever before. "We ran an automated scan last year" is not an answer your compliance officer wants to give.

Generic pentest shops scan your marketing site, hand you a PDF of low-severity findings, and stop. The systems that actually hold client funds and client data never get touched.

◆ What we test

The full broker stack, tested by hand.

01

Client portal / Trader's Room

Authentication, session handling, access control, deposit and withdrawal flows, KYC document storage.

02

Broker CRM

User roles and permissions, data exposure, integration endpoints, back-office access.

03

PSP & payment integrations

API keys and secrets handling, callback/webhook validation, transaction flow tampering.

04

Trading servers

The MetaTrader 4/5 or cTrader servers your platform runs on: exposed services, admin/management interfaces, remote access, and host configuration.

05

Hosting & network perimeter

External attack surface, VPS/dedicated server configuration, firewalling, remote access, exposed management planes.

Every engagement is scoped to your actual stack — not a generic checklist.

◆ How it works

On demand. No retainers, no platform to learn.

Step 01

Book a scoping call

30 minutes with a senior engineer. We map your stack — portal, CRM, PSPs, servers, hosting — and agree what's in scope.

Step 02

Fixed scope, fixed quote

You get a clear proposal: what we'll test, how, and when. No open-ended billing.

Step 03

Manual testing by senior engineers

Real people probing your systems the way a real attacker would — not an automated scanner run.

Step 04

Report and debrief

Findings ranked by real-world impact, with concrete remediation steps, walked through live with your technical team.

Step 05

Retest included

Once you've fixed the critical issues, we verify the fixes.

◆ Why us

Broker-focused, not generic.

We understand the broker stack.

How the Trader's Room, broker CRM, PSP integrations, and the infrastructure behind MT4/MT5 and cTrader are actually deployed — and where they actually break. We test the trading servers as infrastructure; deep platform internals aren't what we oversell.

Manual, human-led testing.

Scanners find what scanners find. Our senior engineers chain findings, test business logic, and go after what matters: client funds and client data.

Boutique by design.

You work directly with the engineers doing the testing — no account managers, no junior staff learning on your infrastructure.

Built for regulated brokers.

We understand the pressure CySEC-regulated firms are under and write our reports so they're useful to your compliance function, not just your sysadmins.

◆ What you get

More than a PDF.

  • Executive summaryPlain-language risk picture for management and compliance.
  • Technical findings reportEvery issue with severity, evidence, reproduction steps, and specific remediation guidance for your stack.
  • Live debriefA working session with your team, not just a PDF in your inbox.
  • Remediation retestConfirmation that critical fixes actually hold, documented.
  • Evidence for your regulator fileA professional penetration test report you can present as part of your resilience-testing and ICT risk documentation.
◆ Pricing

Fixed quotes, no surprises.

Every engagement starts with a free scoping call and ends with a fixed quote — the prices below are where engagements typically start.

One-off audit

From €3,000Per audit

One full audit of your broker stack — scoped on the call, tested by hand, retested after you fix.

  • Full broker stack in scope — Trader's Room, CRM, PSP integrations, trading servers, perimeter
  • Technical findings report + executive summary
  • Live debrief with your team
  • Remediation retest included
  • Evidence for your regulator file (DORA / CySEC)
Book a scoping call →

Ongoing — annual

Best value
From €9,000Per year

The same audit, as a year-long contract — recurring testing for brokers who ship often and answer to a regulator.

  • Everything in the one-off audit
  • Scheduled audits across the year, scoped to what changed
  • Retesting as you fix and ship
  • Priority scheduling — a real date, not a queue
  • Year-round PayaAudit Portal access
  • Periodic summaries written for your compliance function
Book a scoping call →

Enterprise

CustomTailored contract

For multi-brand groups and larger brokers with more entities, more platforms, more scope.

  • Everything in the annual contract
  • Multiple brands, entities, and environments in scope
  • Custom reporting for group-level compliance
  • Dedicated senior engineer contact
  • Bespoke testing windows and cadence
Contact us →

All prices exclude VAT. Final quote is fixed after the free scoping call — no open-ended billing, ever.

◆ FAQ

Fair questions.

No — and be wary of any pentest vendor who says yes. We are not a certification body or an official auditor, and a penetration test alone doesn't make you certified or compliant with anything. What our testing does provide is strong, independent evidence toward the resilience-testing obligations these frameworks expect — DORA, for example, explicitly names penetration testing as part of digital resilience testing. Your auditors and regulators want to see it done properly; we give you that.

No. Automated tools are a small part of reconnaissance at most. The testing itself is done by hand, by senior security engineers. That's the only way to find business-logic flaws — like a withdrawal flow that can be abused — that no scanner will ever flag.

We're senior software and security engineers who focus on brokers as a market. We understand how the stack is deployed and test the trading servers as infrastructure — their exposure, access, and configuration. Deep trading-platform internals aren't our headline claim; finding the flaws that put client funds and data at risk is. If a job genuinely needs specialist platform depth we don't have yet, we'll say so.

Ask what was actually in scope. If the answer is "the website," your servers, Trader's Room, CRM, and payment integrations have never been tested. Those are the systems holding client money and KYC data.

Scoping exists precisely to prevent that. We agree testing windows, methods, and off-limits actions up front, and we can test against staging environments where appropriate. Production safety rules are written into every engagement.

Engagements are on demand. After the scoping call and agreement, typical lead time is short — we're a boutique team, so we'll give you a real date, not a queue.

A one-off audit starts at €3,000; an ongoing annual contract starts at €9,000/year — see pricing. The scoping call is free and you'll get a fixed quote after it. No open-ended billing.

◆ Final step · Free scoping call

Find out what an attacker would find — before one does.

One scoping call. A fixed quote. A manual penetration test of the systems that actually hold your clients' funds and data.

· Manual testing · Fixed quote · Retest included · EU / CySEC aware
Or email us — [email protected]
Thanks — we'll be in touch shortly to schedule your scoping call.