Services / Web app & API

Web application & API test

A hands-on test of your application and its APIs, run the way an attacker with an account would: every role, every workflow, and the API calls behind the interface.

What's included

  • Manual testing aligned with the OWASP Web Security Testing Guide and the OWASP API Security Top 10, supported by tooling rather than driven by it
  • Authentication, session management, access control and multi-tenancy isolation
  • Injection, file handling, business-logic and workflow abuse testing
  • Findings rated with CVSS, each with reproduction steps and evidence
  • Fix guidance written for the developer who has to make the change
  • One retest of fixed findings, included

Scope

  • One web application and the APIs it uses
  • All user roles you provide, plus unauthenticated testing
  • Staging or production, agreed in the rules of engagement

Who it's for

  • SaaS teams whose customers ask for a recent penetration test
  • Teams shipping a significant release or a new authentication model
  • Companies preparing for ISO 27001 or customer security reviews

What you get

  • Technical report: findings, evidence, reproduction steps, remediation
  • Management summary your board or customers can read
  • Optional debrief call with the engineering team
  • Retest letter confirming what has been fixed

Report delivered within 5 working days of testing ending. One retest of fixed findings included, within 60 days.

deliverables/ What lands in your inbox
report/
  technical-report.pdf      findings, evidence, fixes
  management-summary.pdf    for the board or a customer
  findings.csv              straight into your tracker
retest/
  retest-letter.pdf         after you've fixed things

How the engagement runs

01

Scope

A short call about the application, its roles and what would hurt most if it broke. You get a fixed-price proposal and dates.

02

Authorise

Rules of engagement, authorisation and an NDA if you want one. Testing starts only once these are signed.

03

Map

Reconnaissance and mapping: every route, role, parameter and API call that makes up the attack surface.

04

Test

Manual testing against the OWASP guides, supported by tooling. Critical findings are reported the moment they are confirmed, not held for the report.

05

Report

Findings with evidence, reproduction steps, CVSS ratings and fix guidance written for developers, plus a summary for everyone else.

06

Retest

Once you have fixed things, a retest confirms it, and you get a letter you can show customers or auditors.

Questions

Do you test in production?

Only if you ask for it and we agree limits in writing first. Most tests run against a staging environment that matches production, with test accounts for each role. Where production testing is necessary, we agree timing, rate limits and a contact who can stop the test immediately.

What do you need from us?

A URL, accounts for each user role, a short description of what matters most in the application, and signed authorisation. If the application sits behind a WAF or IP allow-list, we will need to be allowed through or explicitly tested with it in place.

request a scope

Get a fixed price for your application

A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.

Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days