Application Security
Web apps & APIs — Manual penetration testing and secure code review for the applications your business runs on. We test the way an attacker does — chaining authorization flaws, business-logic abuse and broken session handling into outcomes you can act on — rather than reporting whatever a scanner flagged. Every finding is validated by hand before it reaches your report.
Is this the right engagement?
- You ship a web application or API that handles customer data, money, or access to either
- A customer, auditor, or insurer has asked for an independent application penetration test
- You are preparing for SOC 2, ISO 27001, PCI DSS, or a security questionnaire from a large buyer
- You have run scanners and want to know what a human attacker would actually do with the results
Deliverables
- Executive summary describing business impact, material risk and remediation priorities
- Technical findings report with affected endpoints, evidence, severity, reproduction steps and remediation guidance
- Proof-of-concept exploitation for every finding we claim is exploitable
- Live technical debrief with your engineers — not a report dropped in an inbox
- One bounded remediation retest within 30 days of final report delivery
- Retest report you can hand to an auditor or customer
Engagements in this solution
Each engagement is scoped around what you are actually running. Where pricing is standardized you can estimate it online in a couple of minutes.
Application Penetration Test
ESTIMATE ONLINEManual testing of a web application and its APIs across authenticated roles — authentication, authorization, session management, input handling, business logic and data exposure.
Targeted Secure Code Review
ESTIMATE ONLINEManual review of one security-critical module — authentication, authorization, cryptography, or payment logic — across your agreed languages and frameworks.
Comprehensive Secure Code Review
ESTIMATE ONLINEFull-codebase review across multiple services and repositories, including secure-design assessment for larger or multi-language platforms.
How the work is run
The same sequence runs underneath every engagement in this solution — specialised here for application security.
Scope & authorize
Application inventory, authenticated roles, endpoint count and out-of-bounds systems agreed in writing. Test accounts provisioned and rules of engagement executed.
Map & enumerate
Manual walkthrough of every authenticated role, mapping the real attack surface — including endpoints your documentation does not mention.
Test & exploit
Manual testing against OWASP ASVS and real attacker tradecraft: broken access control, injection, business-logic abuse, session and token handling, and chained multi-step attacks.
Validate
Every finding is reproduced and exploited to establish real impact. Anything we cannot demonstrate is reported as an observation, not a vulnerability.
Report & brief
Findings written for the engineers who will fix them, with an executive summary for the people who fund the fix. Walked through live.
Remediate & retest
One bounded retest validates every reported finding, so "resolved" means resolved.
What to expect, and when
Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.
| Stage | Duration | What happens |
|---|---|---|
| Scope & authorize | 2–5 business days | Targets, objectives and rules of engagement agreed in writing. Authorization signed before anything is touched. |
| Test & exploit | 5–10 business days | Manual testing mapped to real attacker tradecraft. Findings are exploited and chained, not just flagged. |
| Report & brief | 3–5 business days | Findings report delivered, then walked through live with the engineers and the executives who own the risk. |
| Remediate & retest | Within 30 days | One bounded retest validates fixes against every reported finding. |
| Total | 3–5 weeks | From signed authorization to retest report, for a standard scope. |
What you can hold us to
Commitments that are checkable, not adjectives.
Automated tooling is used for coverage, never for findings. Every reported issue is hand-validated.
If we report it as exploitable, the report contains the proof-of-concept that makes it exploitable.
One bounded remediation retest is part of the engagement, not an upsell.
The scope and fee are agreed before testing starts. Scope changes require a written change order — no surprise invoices.
No testing begins until the agreement, statement of work and rules of engagement are executed.
Before you ask us
Do you need production access?
A representative staging environment is preferred. If only production is available we agree non-destructive constraints in the rules of engagement before testing begins.
Will testing take our application down?
Destructive and availability-impacting techniques are excluded unless you separately authorize them in writing.
Can you test behind SSO?
Yes. Federated identity and multi-tenant authorization are common in our scopes — they factor into the estimate rather than blocking it.