Web and API penetration testing

Hands-on testing of your web app and the APIs behind it, mapped to OWASP WSTG, ASVS and the API Security Top 10.

If one customer can see another customer’s data, we’ll find the route that lets them.

What we test

Out of scope stays out. We ask first.

  • Authentication and sessions

    Login, MFA, password reset, and how tokens are issued, stored and revoked.

  • Access control

    Every role, object and tenant, on every route that reads or changes data.

  • Business logic

    Workflows, limits, payments and state changes no scanner can reason about.

  • Input handling

    Injection, templates, file uploads and the parsers behind them.

  • APIs

    REST and GraphQL, object-level authorisation, mass assignment, rate limits and error leaks.

  • Browser and configuration

    Headers, CORS, CSP, caching, and secrets in front-end bundles.

How we test

  1. Scoping

    Targets, roles, test accounts, environments and dates. Then a fixed written quote.

  2. Mapping

    A crawl of the app and a read of the API schema: endpoints, roles, data flows.

  3. Automated baseline

    Scanners and Semgrep clear the common classes, so our hours go to the hard parts.

  4. Manual testing

    WSTG and the API Top 10 by hand, mostly access control and business logic.

  5. Proof

    A small, safe proof of concept for each issue.

  6. Report and retest

    A walkthrough with your engineers, then a free retest of the fixes.

A report your engineers can act on

  • Severity, evidence, reproduction steps and a fix for every finding.
  • A plain-language summary for whoever signs off.
  • WSTG, ASVS and API Top 10 references on each one.
  • A free retest in an agreed window, and an updated report.

How a finding reads

V-017ExampleSeverity: High

Any signed-in user can download any customer’s invoice

Weakness
CWE-639
Where
Billing API, invoice download route
Impact
Any signed-in user could download invoices that belong to another customer.
Fix
Check on the server that each invoice belongs to the caller’s account, on every route that loads an object by ID.
Fixed · retested

Standards and tools

Findings mapped to
  • OWASP WSTG
  • OWASP ASVS
  • OWASP API Security Top 10
  • NIST SP 800-115
Tools we use
  • Burp Suite
  • Semgrep
  • CodeQL
  • Nmap
Black box, grey box or white box?

Grey box by default: test accounts for each role, plus your API docs. White box adds a code review with Semgrep and CodeQL. Black box shows exactly what an outsider sees.

How long does a test take?

Scope decides it: roles, endpoints and workflows. We estimate on the scoping call, and the quote fixes the dates.

Do you test production or staging?

Staging that mirrors production, so we can push risky paths without touching real data. If it has to be production, limits and hours go in writing, and you can pause us at any time.

What do you need from us?

Test accounts for each role, API docs or an OpenAPI or Postman file, a technical contact, and written authorisation from whoever owns the system.

Tell us about your app and API

Send the scope and your deadline, and we’ll set up a call.