Web / API Pentest
A fixed-window manual penetration test of a single application and its API surface. Testers work from a real account in each role you have, chase the access-control and business-logic flaws that no scanner reaches, and prove impact with a working request rather than a tool signature. Every finding ships with the exact steps to reproduce it and the fix we would make.
Timeline
Two to four weeks end to end for a standard application: a week to scope and get access, one to two weeks of testing, and the report within three business days of the last test day.
You get
- Written report — executive summary and per-finding technical detail
- Reproduction steps and request/response evidence for every finding
- Severity, business impact and a recommended fix per finding
If any of these is your week, this is the service.
An enterprise buyer has asked for a pentest report
Procurement or a security questionnaire has stalled a deal and wants a third-party report with a named tester and a date on it.
What we do
A standard-scope test with a signed, letterheaded report and an attestation letter you can hand straight to the buyer.
You just shipped multi-tenancy or a new role
Tenant isolation and role boundaries are where the expensive bugs live, and they are invisible to an unauthenticated scan.
What we do
A test driven entirely from real accounts in every role and tenant, focused on IDOR and privilege boundaries.
You ship weekly and have never been tested
The product has grown past the point where the team can reason about who can reach what, and nobody outside has ever tried.
What we do
A full-surface first test, then a lighter retest each release — or a bounty program once the obvious findings are closed.
Your API is public and your docs are complete
A documented API is a map for an attacker as much as for an integrator, and it is usually tested far less than the UI in front of it.
What we do
The API is in scope by default, worked from your own collection or specification rather than through the interface.
Every step, and what leaves our hands at the end of it.
- 01
Scope & access
We agree the hosts, endpoints and roles in writing, and you issue test accounts. Prohibited techniques and testing windows are named up front.
→ Signed scope & authorisation
- 02
Reconnaissance
Map the surface: routes, parameters, auth flows, third-party calls and the exact shape of every role's permissions.
→ Surface map
- 03
Manual testing
Access control, authentication, injection, SSRF and business logic, worked by hand from every role. Tooling assists; it never decides.
- 04
Proof & triage
Each finding is reproduced end to end, rated by real impact rather than CVSS alone, and duplicates are collapsed.
→ Findings with reproduction steps
- 05
Report & walkthrough
A written report plus a live session with your engineers, so the fix is understood and not just filed.
→ Full report + attestation letter
- 06
Retest
Once you have shipped fixes we re-run every finding and reissue the report with each one marked closed.
→ Retest addendum
Deliverables.
- Written report — executive summary and per-finding technical detail
- Reproduction steps and request/response evidence for every finding
- Severity, business impact and a recommended fix per finding
- An ordered remediation plan your engineers can work top-down
- Letterheaded attestation letter for customers and auditors
- One free retest within 90 days, with a reissued report
Before we can quote.
- 01The hostnames and API base URLs in scope
- 02Test accounts in every role you have, and every tenant if multi-tenant
- 03API documentation or an OpenAPI / Postman collection, if one exists
- 04Any area we must not touch, and any maintenance window to avoid
- 05Whether you need an attestation letter, and who it is addressed to
Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.
Web / API Pentest, answered.
Will this take our site down?
No. We test production only with your written consent, exclude denial-of-service entirely, and agree rate limits and a window before we start. Destructive checks run against staging or not at all.
How is this different from a bug bounty program?
A pentest is a fixed window with a named team and a guaranteed report on a date. A bounty program is continuous and pays per valid finding, with no guarantee anyone looks this month. Most teams do a pentest first, close what it finds, then open a program to keep the surface honest.
Do you test the API separately?
It is one engagement. The API is where most access-control findings live, so it is in scope by default rather than an add-on.
What happens if you find nothing critical?
You get the same report, covering the surface we tested and what held up. That is a defensible answer for a buyer or an auditor, and it is the outcome we want on your second test.
Scope a Web / API Pentest.
Web / API Pentest is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.