Skip to content

Testing · Application

Web Application & API Testing.

Manual, exploit-led penetration testing of the applications and APIs your business runs on — the authorisation, workflow and logic flaws no scanner will ever find.

At a glance

Surface
Application
Execution
Manual, senior-led
Retest
Included, no charge
Proposal
Within one business day

Scope

Tested right, proven by exploitation.

Every assessment is executed by senior operators against a threat model built for your application, then validated end to end before it reaches your report.

Web application assessment

Authenticated, multi-role testing across the full OWASP surface and beyond — injection, deserialisation, SSRF, file handling and chained exploits.

1–3 weeks

API & GraphQL testing

REST, GraphQL and gRPC endpoints tested for broken object-level authorisation, mass assignment, rate-limit abuse and schema exposure.

1–2 weeks

Business logic abuse

Payment, credit, workflow and entitlement paths abused the way a motivated attacker or fraudulent customer would.

3–7 days

Authentication & session testing

SSO, OAuth, OIDC, MFA bypass, token handling, password reset and account takeover chains.

3–7 days

Source-assisted (grey/white box) review

Code-informed testing that maps discovered behaviour back to the exact vulnerable function.

2–4 weeks

Remediation retest

Free retest of every fixed finding, with a closure letter your auditors and customers accept.

Within 90 days

Method

How the engagement runs.

Nothing starts before the authorisation letter is signed and the blast radius is agreed.

  1. 01

    Scoping

    Targets, roles, rules of engagement, test accounts and a signed authorisation letter.

  2. 02

    Reconnaissance

    Mapping, threat modelling and attack-surface enumeration against your architecture.

  3. 03

    Exploitation

    Manual attack execution, chaining and privilege escalation — criticals reported same day.

  4. 04

    Reporting

    Reproducible write-ups, business impact, CVSS and prioritised remediation guidance.

  5. 05

    Retest

    Verification of fixes, updated report and an attestation letter.

Deliverables

What lands on your desk.

  • Executive summary written for non-technical stakeholders
  • Technical findings with full reproduction steps and evidence
  • CVSS v4.0 scoring with real-world business impact ratings
  • Prioritised remediation roadmap with effort estimates
  • OWASP ASVS / API Top 10 coverage matrix
  • Free retest report and attestation letter
  • Redacted customer-shareable report on request

Indicative timeline

Kickoff to closure.

Week 0
Scoping call, rules of engagement, credentials issued
Days 1–3
Reconnaissance, mapping and threat modelling
Days 3–12
Active manual testing, daily critical notifications
Days 13–15
Draft report, technical walkthrough, executive readout
Within 90 days
Free retest of remediated findings and closure letter

Enquire

Start a Web Application & API Testing conversation.

Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.

PRACTICE 01 OF 07

0/2000

Start here

Find the flaw before an attacker does.

Send us the scope. You'll have a fixed-price proposal, a named lead tester and a start date within one business day.