SOLUTION

Application Security

Web apps & APIs — Manual penetration testing and secure code review for the applications your business runs on. We test the way an attacker does — chaining authorization flaws, business-logic abuse and broken session handling into outcomes you can act on — rather than reporting whatever a scanner flagged. Every finding is validated by hand before it reaches your report.

WHO THIS IS FOR

Is this the right engagement?

  • You ship a web application or API that handles customer data, money, or access to either
  • A customer, auditor, or insurer has asked for an independent application penetration test
  • You are preparing for SOC 2, ISO 27001, PCI DSS, or a security questionnaire from a large buyer
  • You have run scanners and want to know what a human attacker would actually do with the results
When it is notIf you need continuous automated scanning of every build, that is a tooling problem, not a pentest — we will tell you so rather than sell you an engagement.
WHAT YOU RECEIVE

Deliverables

  • Executive summary describing business impact, material risk and remediation priorities
  • Technical findings report with affected endpoints, evidence, severity, reproduction steps and remediation guidance
  • Proof-of-concept exploitation for every finding we claim is exploitable
  • Live technical debrief with your engineers — not a report dropped in an inbox
  • One bounded remediation retest within 30 days of final report delivery
  • Retest report you can hand to an auditor or customer
METHODOLOGY

How the work is run

The same sequence runs underneath every engagement in this solution — specialised here for application security.

Scope & authorize

Application inventory, authenticated roles, endpoint count and out-of-bounds systems agreed in writing. Test accounts provisioned and rules of engagement executed.

Map & enumerate

Manual walkthrough of every authenticated role, mapping the real attack surface — including endpoints your documentation does not mention.

Test & exploit

Manual testing against OWASP ASVS and real attacker tradecraft: broken access control, injection, business-logic abuse, session and token handling, and chained multi-step attacks.

Validate

Every finding is reproduced and exploited to establish real impact. Anything we cannot demonstrate is reported as an observation, not a vulnerability.

Report & brief

Findings written for the engineers who will fix them, with an executive summary for the people who fund the fix. Walked through live.

Remediate & retest

One bounded retest validates every reported finding, so "resolved" means resolved.

TIMELINE

What to expect, and when

Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.

StageDurationWhat happens
Scope & authorize2–5 business daysTargets, objectives and rules of engagement agreed in writing. Authorization signed before anything is touched.
Test & exploit5–10 business daysManual testing mapped to real attacker tradecraft. Findings are exploited and chained, not just flagged.
Report & brief3–5 business daysFindings report delivered, then walked through live with the engineers and the executives who own the risk.
Remediate & retestWithin 30 daysOne bounded retest validates fixes against every reported finding.
Total3–5 weeksFrom signed authorization to retest report, for a standard scope.
HOW WE WORK

What you can hold us to

Commitments that are checkable, not adjectives.

Manual-first

Automated tooling is used for coverage, never for findings. Every reported issue is hand-validated.

Proof, not probability

If we report it as exploitable, the report contains the proof-of-concept that makes it exploitable.

Retest included

One bounded remediation retest is part of the engagement, not an upsell.

Fixed scope, fixed fee

The scope and fee are agreed before testing starts. Scope changes require a written change order — no surprise invoices.

Testing under authorization only

No testing begins until the agreement, statement of work and rules of engagement are executed.

QUESTIONS

Before you ask us

Do you need production access?

A representative staging environment is preferred. If only production is available we agree non-destructive constraints in the rules of engagement before testing begins.

Will testing take our application down?

Destructive and availability-impacting techniques are excluded unless you separately authorize them in writing.

Can you test behind SSO?

Yes. Federated identity and multi-tenant authorization are common in our scopes — they factor into the estimate rather than blocking it.

See a price range in two minutes.

Select your scope in the estimator and get an indicative range, an outline timeline and what is included — no call required.

Choose which optional cookies BNO Security Group may use. You can update this choice at any time.

Necessary cookiesRequired for security, core features, and consent storage.
Always active
Analytics cookiesHelp us understand site traffic and improve the website.
Advertisement cookiesSupport relevant campaign measurement and advertising.