Assessment
Automated Assessment
Nothing has ever been tested, and you want to know where you stand.
What it covers
Automated coverage of the application and the API behind it, with every result verified by a tester before it reaches you.
- Automated coverage of the application and the API behind it
- Known vulnerabilities in components and dependencies
- Missing or misconfigured security controls and headers
- Files, directories and endpoints exposed that should not be
- The input handling and injection classes tooling can reach
What a tool will not find is the logic: it does not know which endpoint was supposed to check the caller's role, or that one customer can read another's invoices. If that is the risk you are carrying, the manual tiers are the ones that answer it, and we will say so.
Every assessment
A verified report and a retest
Every reported result is checked by a person. Your engineers get reproducible findings, and we verify their fixes under the published retest terms.
Get a baseline
We look at the application first, agree the scope in writing, and quote before any testing starts.