Assessment
Deep Dive
If this application is compromised, it is not an inconvenience.
What it covers
For applications where money moves, records are sensitive, or something in there can act on a customer's behalf.
- Multi-role and multi-tenant authorisation, worked through rather than spot-checked
- Payment, billing and anything else that moves money
- Privileged and administrative functionality
- The API estate, including what one service will do on behalf of another
- Business logic and state, driven the ways the design does not expect
- AI components: what the model can reach, and what it may do with it
Scope here is built for the application rather than taken off a list, so this one starts with a conversation. Ten days is where it begins; how far past that it goes depends on what we find.
Every assessment
A verified report and a retest
Every reported result is checked by a person. Your engineers get reproducible findings, and we verify their fixes under the published retest terms.
Discuss your application
We look at the application first, agree the scope in writing, and quote before any testing starts.