Assessment
Application Pentest
Real users, real data, and a reason to be sure.
What it covers
Your application and the APIs behind it, worked through by hand: role by role, feature by feature.
- Authentication, authorisation and role separation
- Access control across accounts and across tenants
- The API surface, including the methods the front end never calls
- Business logic: your rules on limits, sequences, prices and ownership
- Input handling and injection
- Client-side security where the application puts trust there
What gets tested is agreed before anything starts. Not every category above applies to every application, and we would rather spend the days where the risk is than tick all of them.
Every assessment
A verified report and a retest
Every reported result is checked by a person. Your engineers get reproducible findings, and we verify their fixes under the published retest terms.
Request an assessment
We look at the application first, agree the scope in writing, and quote before any testing starts.