PayaAudit by Paya Labs is on-demand, manual penetration testing built for Forex/CFD brokers — senior security engineers who test your Trader's Room, CRM, PSP integrations, and the servers your MT4/MT5 or cTrader platform runs on, not just your marketing site.
Most brokers run a stack that generic security firms never look past the front page of.
The MT4/MT5 or cTrader servers behind your platform must be reachable by thousands of client terminals. One forgotten admin port, one weak gateway credential, one exposed management interface — and an attacker isn't defacing your website, they're pulling account data or moving money.
Client balances, withdrawal flows, KYC documents — passports, proof of address, banking details. A single IDOR or broken access control in the client portal turns into fraudulent withdrawals and a reportable data breach in the same afternoon.
Broker CRMs concentrate every lead, every client record, every deposit. Payment integrations pass sensitive data and callbacks between systems built by different vendors. These seams are exactly where attackers live — and exactly where a website-only scan never looks.
DORA is now in force across the EU, and it explicitly expects financial entities to test their digital resilience — penetration testing included. CySEC-regulated brokers are being asked harder questions about ICT risk than ever before. "We ran an automated scan last year" is not an answer your compliance officer wants to give.
Generic pentest shops scan your marketing site, hand you a PDF of low-severity findings, and stop. The systems that actually hold client funds and client data never get touched.
Authentication, session handling, access control, deposit and withdrawal flows, KYC document storage.
User roles and permissions, data exposure, integration endpoints, back-office access.
API keys and secrets handling, callback/webhook validation, transaction flow tampering.
The MetaTrader 4/5 or cTrader servers your platform runs on: exposed services, admin/management interfaces, remote access, and host configuration.
External attack surface, VPS/dedicated server configuration, firewalling, remote access, exposed management planes.
Every engagement is scoped to your actual stack — not a generic checklist.
30 minutes with a senior engineer. We map your stack — portal, CRM, PSPs, servers, hosting — and agree what's in scope.
You get a clear proposal: what we'll test, how, and when. No open-ended billing.
Real people probing your systems the way a real attacker would — not an automated scanner run.
Findings ranked by real-world impact, with concrete remediation steps, walked through live with your technical team.
Once you've fixed the critical issues, we verify the fixes.
How the Trader's Room, broker CRM, PSP integrations, and the infrastructure behind MT4/MT5 and cTrader are actually deployed — and where they actually break. We test the trading servers as infrastructure; deep platform internals aren't what we oversell.
Scanners find what scanners find. Our senior engineers chain findings, test business logic, and go after what matters: client funds and client data.
You work directly with the engineers doing the testing — no account managers, no junior staff learning on your infrastructure.
We understand the pressure CySEC-regulated firms are under and write our reports so they're useful to your compliance function, not just your sysadmins.
No — and be wary of any pentest vendor who says yes. We are not a certification body or an official auditor, and a penetration test alone doesn't make you certified or compliant with anything. What our testing does provide is strong, independent evidence toward the resilience-testing obligations these frameworks expect — DORA, for example, explicitly names penetration testing as part of digital resilience testing. Your auditors and regulators want to see it done properly; we give you that.
No. Automated tools are a small part of reconnaissance at most. The testing itself is done by hand, by senior security engineers. That's the only way to find business-logic flaws — like a withdrawal flow that can be abused — that no scanner will ever flag.
We're senior software and security engineers who focus on brokers as a market. We understand how the stack is deployed and test the trading servers as infrastructure — their exposure, access, and configuration. Deep trading-platform internals aren't our headline claim; finding the flaws that put client funds and data at risk is. If a job genuinely needs specialist platform depth we don't have yet, we'll say so.
Ask what was actually in scope. If the answer is "the website," your servers, Trader's Room, CRM, and payment integrations have never been tested. Those are the systems holding client money and KYC data.
Scoping exists precisely to prevent that. We agree testing windows, methods, and off-limits actions up front, and we can test against staging environments where appropriate. Production safety rules are written into every engagement.
Engagements are on demand. After the scoping call and agreement, typical lead time is short — we're a boutique team, so we'll give you a real date, not a queue.
Depends on scope — a perimeter-plus-portal test is very different from a full-stack engagement. The scoping call is free and you'll get a fixed quote after it. No open-ended billing.
One scoping call. A fixed quote. A manual penetration test of the systems that actually hold your clients' funds and data.