web application & api penetration testing

Find the flaws before someone else does.

Manual testing of your web application and the APIs behind it, for SaaS, health-tech and medical-device software. Fixed price agreed before we start, a report your developers can act on, and a free retest when you have fixed things.

Fixed-price quote within 2 working days of the scoping call.

findings-summary.txt Illustrative extract
# severity summary — example output, not a real client
CRITICAL  1  Broken access control: role B reads role A records
HIGH      2  Tenant isolation bypass via object identifier
HIGH         Session not invalidated after password change
MEDIUM    4  ...
LOW       6  ...

→ each finding: evidence, reproduction steps, CVSS, fix guidance
→ retest of fixed findings included

what you get

A test you can hand to engineering, and a summary you can hand to a customer.

Tested by hand

Scanners find the obvious. Access-control gaps, tenant isolation failures and business-logic abuse need someone who understands what the application is for.

A report people act on

Every finding has evidence, reproduction steps, a CVSS rating and fix guidance written for the developer who has to make the change.

Retest included

Fix the findings and we verify them, then issue a retest letter you can show customers and auditors.

One named tester

You know who is testing your application, and you talk to that person directly. No hand-off to a junior after the sales call.

how it runs

Six steps, no surprises.

You always know what is happening, what has been found so far, and what happens next. Critical findings are reported the moment they are confirmed.

01

Scope

A short call about the application, its roles and what would hurt most if it broke. You get a fixed-price proposal and dates.

02

Authorise

Rules of engagement, authorisation and an NDA if you want one. Testing starts only once these are signed.

03

Map

Reconnaissance and mapping: every route, role, parameter and API call that makes up the attack surface.

04

Test

Manual testing against the OWASP guides, supported by tooling. Critical findings are reported the moment they are confirmed, not held for the report.

who-this-is-for.md Typical clients
SaaS            customer security reviews, ISO 27001 evidence,
                a new release or authentication model

Health-tech     portals handling patient or clinical data,
                NHS and hospital security questionnaires

Medical device  SaMD and connected-device web interfaces
                needing evidence for FDA or EU MDR files

Scale-ups       growing fast, no in-house security engineer

who it's for

Regulated software is where this gets interesting.

Testing a web application well means understanding what it is supposed to do, and who is supposed to be able to do it. That is harder, and more valuable, when the application carries clinical or personal data and someone will eventually audit it.

The medical-device package exists because device makers need more than a findings list: they need test evidence structured for a submission or a technical file.

Alex Adamovici

who tests it

One tester, named, on every engagement.

I'm Alex Adamovici. I've spent my career in security engineering across regulated industries: cloud architecture, identity and access management, and the security evidence that regulated products have to produce. I test the applications I'm engaged for personally, and I write the report myself.

request a scope

Find out what a test would cost

A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.

Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days