Services / Web app & API
Web application & API test
A hands-on test of your application and its APIs, run the way an attacker with an account would: every role, every workflow, and the API calls behind the interface.
What's included
- Manual testing aligned with the OWASP Web Security Testing Guide and the OWASP API Security Top 10, supported by tooling rather than driven by it
- Authentication, session management, access control and multi-tenancy isolation
- Injection, file handling, business-logic and workflow abuse testing
- Findings rated with CVSS, each with reproduction steps and evidence
- Fix guidance written for the developer who has to make the change
- One retest of fixed findings, included
Scope
- One web application and the APIs it uses
- All user roles you provide, plus unauthenticated testing
- Staging or production, agreed in the rules of engagement
Who it's for
- SaaS teams whose customers ask for a recent penetration test
- Teams shipping a significant release or a new authentication model
- Companies preparing for ISO 27001 or customer security reviews
What you get
- Technical report: findings, evidence, reproduction steps, remediation
- Management summary your board or customers can read
- Optional debrief call with the engineering team
- Retest letter confirming what has been fixed
Report delivered within 5 working days of testing ending. One retest of fixed findings included, within 60 days.
report/ technical-report.pdf findings, evidence, fixes management-summary.pdf for the board or a customer findings.csv straight into your tracker retest/ retest-letter.pdf after you've fixed things
How the engagement runs
Scope
A short call about the application, its roles and what would hurt most if it broke. You get a fixed-price proposal and dates.
Authorise
Rules of engagement, authorisation and an NDA if you want one. Testing starts only once these are signed.
Map
Reconnaissance and mapping: every route, role, parameter and API call that makes up the attack surface.
Test
Manual testing against the OWASP guides, supported by tooling. Critical findings are reported the moment they are confirmed, not held for the report.
Report
Findings with evidence, reproduction steps, CVSS ratings and fix guidance written for developers, plus a summary for everyone else.
Retest
Once you have fixed things, a retest confirms it, and you get a letter you can show customers or auditors.
Questions
Do you test in production?
Only if you ask for it and we agree limits in writing first. Most tests run against a staging environment that matches production, with test accounts for each role. Where production testing is necessary, we agree timing, rate limits and a contact who can stop the test immediately.
What do you need from us?
A URL, accounts for each user role, a short description of what matters most in the application, and signed authorisation. If the application sits behind a WAF or IP allow-list, we will need to be allowed through or explicitly tested with it in place.
Other services
Medical-device & SaMD web application test
The same testing, plus the evidence structure that regulatory submissions and notified-body reviews ask for.
From £5,950
Details →Cloud configuration review
A configuration and identity review of the Azure environment your application runs in, with prioritised, practical fixes.
From £1,950
Details →request a scope
Get a fixed price for your application
A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.
Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days