Testing · Application
Web Application & API Testing.
Manual, exploit-led penetration testing of the applications and APIs your business runs on — the authorisation, workflow and logic flaws no scanner will ever find.
At a glance
- Surface
- Application
- Execution
- Manual, senior-led
- Retest
- Included, no charge
- Proposal
- Within one business day
Scope
Tested right, proven by exploitation.
Every assessment is executed by senior operators against a threat model built for your application, then validated end to end before it reaches your report.
Web application assessment
Authenticated, multi-role testing across the full OWASP surface and beyond — injection, deserialisation, SSRF, file handling and chained exploits.
1–3 weeks
API & GraphQL testing
REST, GraphQL and gRPC endpoints tested for broken object-level authorisation, mass assignment, rate-limit abuse and schema exposure.
1–2 weeks
Business logic abuse
Payment, credit, workflow and entitlement paths abused the way a motivated attacker or fraudulent customer would.
3–7 days
Authentication & session testing
SSO, OAuth, OIDC, MFA bypass, token handling, password reset and account takeover chains.
3–7 days
Source-assisted (grey/white box) review
Code-informed testing that maps discovered behaviour back to the exact vulnerable function.
2–4 weeks
Remediation retest
Free retest of every fixed finding, with a closure letter your auditors and customers accept.
Within 90 days
Method
How the engagement runs.
Nothing starts before the authorisation letter is signed and the blast radius is agreed.
- 01
Scoping
Targets, roles, rules of engagement, test accounts and a signed authorisation letter.
- 02
Reconnaissance
Mapping, threat modelling and attack-surface enumeration against your architecture.
- 03
Exploitation
Manual attack execution, chaining and privilege escalation — criticals reported same day.
- 04
Reporting
Reproducible write-ups, business impact, CVSS and prioritised remediation guidance.
- 05
Retest
Verification of fixes, updated report and an attestation letter.
Deliverables
What lands on your desk.
- Executive summary written for non-technical stakeholders
- Technical findings with full reproduction steps and evidence
- CVSS v4.0 scoring with real-world business impact ratings
- Prioritised remediation roadmap with effort estimates
- OWASP ASVS / API Top 10 coverage matrix
- Free retest report and attestation letter
- Redacted customer-shareable report on request
Indicative timeline
Kickoff to closure.
- Week 0
- Scoping call, rules of engagement, credentials issued
- Days 1–3
- Reconnaissance, mapping and threat modelling
- Days 3–12
- Active manual testing, daily critical notifications
- Days 13–15
- Draft report, technical walkthrough, executive readout
- Within 90 days
- Free retest of remediated findings and closure letter
Enquire
Start a Web Application & API Testing conversation.
Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.
PRACTICE 01 OF 07
Start here
Find the flaw before an attacker does.
Send us the scope. You'll have a fixed-price proposal, a named lead tester and a start date within one business day.
