Web application & API penetration test
Where is your web application or API vulnerable?
We examine technical vulnerabilities and flaws in how your web application or API works. This includes login, access rights, input handling and business logic.
Roles, data and logic
Three questions we answer
- Are accounts and sessions properly protected?
- Do roles and customer data remain separate?
- Can functions or processes be misused?
When is this relevant?
How do new features and integrations change security?
New features, additional user roles and integrations change how data is processed. We test security in the context of how your application works.
- You are preparing a new application or a major release.
- You are adding user roles, customer environments or API integrations.
- You process data for which inappropriate access could have serious consequences.
- You want an independent test of existing security measures.
The assessment
What do we assess?
Your environment and assessment question determine the content. We agree in advance which elements we will examine.
01
Authentication and sessions
We examine login, access recovery and session management. We test how the application handles the available accounts and relevant security settings.
02
Authorisation and data separation
We check whether a user can access only the permitted functions and data. Where there are multiple roles or customer environments, we also examine the boundaries between those environments.
03
Input and application logic
We examine how input, files and process steps are handled. We look at both technical vulnerabilities and ways to bypass the intended operation of a process.
04
APIs and integrations
We test the agreed API endpoints, tokens and access controls in conjunction with the application. Documentation and test accounts help us examine less visible functions too.
Defining the scope together
A scope that fits your question.
We determine which applications, roles, processes and APIs cover the assessment question. We agree on the available accounts and documentation to match the required depth.
What do we agree in advance?
- Application version, URLs, API endpoints and relevant integrations.
- Test accounts for the different roles or customer environments.
- Important processes, test data and available documentation.
- Test environment, testing period and coordination with developers.
We can define a separate scope for examining source code, mobile apps or the underlying infrastructure. The proposal states which elements we include.
The result
Insight you can act on.
01
Risks to your application
A summary of the consequences for users, data and business processes.
02
Useful for developers
Findings with reproducible evidence and remediation advice relevant to the functions tested.
03
Priorities for the release
Insight into what needs fixing first and which changes can be retested if required.
Our approach
From the initial question to follow-up.
01
Understanding the application
We discuss the functions, user roles and data that matter.
02
Targeted testing
We combine technical checks with examination of authorisation and process logic.
03
Coordination and reporting
We discuss serious findings during the assessment and deliver a clear report.
04
Verifying remediation
Your developers implement improvements. A targeted retest can follow.
Frequently asked questions
What you need to know in advance.
Can you test just our API?
Yes. We define the scope of the APIs, authentication, roles and relevant data flows. Documentation, sample requests and test accounts help us carry out a focused, in-depth assessment.
Is a black-box test sufficient?
That depends on the question. Examining differences in access between roles usually requires multiple test accounts. We determine in advance what information is needed to test the important risks.
Do you test in production or in a test environment?
A representative test environment can make testing easier. If testing in production is necessary, we make explicit arrangements for test data, permitted activities and availability.
Does this test include a code review?
A code review is an element to be agreed separately. The proposal states whether we examine only the running application or also include source code and configuration.
Our approach
From assessment to clear next steps.
Read how we define the scope, carry out the assessment and discuss the results with you. With a dedicated secure data room and evidence-based reporting.
Discuss your situation
Have your application's boundaries tested.
Discuss your application, release or API with our specialists. We determine which roles and functions we need to examine.
The form is currently unavailable. Use our general contact form or call 036 5367 573.
We use your details to handle your enquiry. Read our privacy policy.