What we test

Web application penetration testing

Authentication, authorisation, injection classes and business logic flaws, guided by the OWASP Top 10 and ASVS.

API penetration testing

Authorisation bypass, excessive data exposure, missing rate limits and broken object-level authorisation across REST and GraphQL.

Vulnerability assessment

Mapping external services, fingerprinting them, correlating known vulnerabilities, and manually clearing the false positives.

Secure source code review

Static analysis paired with manual review, to surface the authorisation logic and trust-boundary flaws scanners never see.

Configuration & architecture review

Cloud identity and permissions, database exposure, transport encryption and how sensitive data is handled.

Security consulting & training

Secure development workshops for engineering teams, plus hands-on code review coaching.

Methodology

We follow published standards so the results can be checked independently — and so you can compare our report against anyone else’s.

  • OWASP Testing Guide

    The baseline for web application test coverage and technique.

  • OWASP ASVS

    Verification levels that define how deep the testing goes.

  • PTES

    The end-to-end framework from pre-engagement through reporting.

  • CVSS 3.1

    A consistent scoring basis for ordering remediation work.

Deliverables

  1. Executive summary

    The risk picture and remediation order, written for decision-makers.

  2. Technical detail

    Reproduction steps, request evidence and screenshots for every finding.

  3. Remediation guidance

    Actionable fixes, with code examples where they help.

  4. Free retest

    One retest once fixes land, closed out with a final report.

Authorisation & data handling

  • All testing stays within a scope both sides have authorised in writing.
  • Anything high-risk or operationally disruptive needs prior consent and a scheduled window.
  • Data obtained during testing is used only for the report, and every copy is deleted at close-out.
  • If you find a security issue in our own services, please report it to our security address.

Got an idea? Start with a conversation

A free fifteen-minute call to check the direction is right, before we talk scope or price.