Englishالعربية Soon
Under attack?
Application assessment · Web, mobile and API

Your application is the one thing you deliberately exposed to everyone.

Manual, role-aware testing of web applications, APIs and mobile clients, covering authorisation, session handling, injection and the business logic no scanner reasons about, with findings ranked by what they would actually cost you.

In scope
Web applications and customer portals
REST and GraphQL APIs
Mobile applications, iOS and Android
Single-page and thick clients
Authenticated areas at every role

Automated scanning is where the engagement starts, not what it is. Broken access control and business logic abuse, the two classes that cost the most, are found by a person reasoning about your application, or not at all.

Perspectives

Tested from three positions, not one

Unauthenticated testing alone misses most of what matters. The interesting findings sit inside the application, between roles.

Unauthenticated

An anonymous attacker on the internet with no credentials and no prior knowledge.

Authenticated, each role

Every privilege level tested separately: and against each other, which is where broken access control surfaces.

Source-assisted

Where source is available, testing is guided by it. Faster, deeper, and it finds what black-box testing cannot reach.

Coverage

Twelve vulnerability classes, tested by hand

Aligned to OWASP methodology, but not limited to a top-ten list. Each class is tested against your application’s actual surface and roles.

01
Broken access control
Whether a user can reach data or functions belonging to somebody else, by changing an identifier, calling an endpoint directly, or escalating between roles. Consistently the highest-impact finding class in application testing.
02
Authentication weaknesses
Credential handling, session establishment, multi-factor enforcement, password reset flows, account lockout and whether a session survives a logout or a password change.
03
Session management
Token generation, scope, expiry, invalidation and transport. A perfectly authenticated session that never expires is an access control failure with extra steps.
04
Injection
SQL, NoSQL, command, LDAP and template injection tested against every input the application accepts, including the ones that are not visible in the interface.
05
Cross-site scripting
Reflected, stored and DOM-based, assessed for what an attacker could actually do with it in your application rather than reported as a generic finding.
06
Business logic abuse
Workflows completed out of order, steps skipped, values manipulated, limits bypassed. No scanner finds these, and they are frequently the most costly.
07
Cryptographic issues
Data in transit and at rest, TLS configuration, certificate handling, weak algorithms and secrets committed where they should not be.
08
Security misconfiguration
Default installs, sample content, verbose errors, missing security headers, permissive CORS and exposed administrative interfaces.
09
Server-side request forgery
Whether the application can be made to reach internal services on an attacker’s behalf, a route into infrastructure that no perimeter control sees.
10
File upload & handling
Type validation, storage location, execution risk, path traversal and whether uploaded content is served back in a dangerous context.
11
API-layer weaknesses
Authorisation per endpoint, mass assignment, rate limiting, input validation and whether the API enforces what the interface implies.
12
Vulnerable components
Third-party libraries and frameworks with known issues, and whether the vulnerable code path is actually reachable in your deployment.
Method

Six phases, and the fourth is most of the engagement

Testing is performed against a staging environment wherever possible. Where production is the only option, destructive checks are excluded and windows are agreed in advance.

01
Scope & authorise
Targets, environments, user roles, exclusions, test windows and escalation contacts agreed, with written authorisation in place before anything begins.
02
Reconnaissance & mapping
The application walked through as a real user. Every page, parameter, endpoint, role and workflow enumerated, including functionality not linked from the interface.
03
Automated baseline
Tooling run to clear the ground quickly and establish coverage. This is the start of the work, not the deliverable.
04
Manual testing
Where the value is. Each vulnerability class tested by hand against the mapped surface, across every role, with attention to authorisation and business logic that no tool reasons about.
05
Exploitation & impact
Findings exercised in a controlled way to establish real impact: what data was reachable, what action was possible, and what it would cost you.
06
Report & retest
Findings ranked by business impact with reproduction steps and evidence, a debrief with your engineers, and a retest once remediation is complete.
Deliverable

What the report contains

An executive summary a non-technical reader can act on, then per-finding detail: the affected component and role, how it was reached, what it exposed, reproduction steps, evidence and the specific change that fixes it. Ranked by business impact rather than by scanner severity.

Talk to an engineer →

Deliverable

Retest included

Fixes are verified after remediation and the report reissued to reflect your current state. A finding is not closed because somebody said it was.

Penetration testing →

Related

What deepens or replaces it

Secure code review

Where source is available, review finds implementation flaws testing cannot reach from outside.

Threat modelling

If the same class keeps recurring, the cause is a design decision rather than individual bugs.

WAF and application shielding

Runtime protection in front of the findings you cannot fix quickly.

Test the one that holds the data.

A scoping call establishes the roles, the environments and the exclusions. We will tell you if a narrower test would answer your question.