Penetration testing
API penetration testing
We test REST and GraphQL APIs against the authorization, data-exposure and abuse cases that matter most to machine interfaces.
What we test
Where we look
When you share an OpenAPI or GraphQL schema we use it to drive complete coverage of every documented operation.
- Broken object- and function-level authorization (BOLA / BFLA)
- Authentication & token handling — keys, JWTs, OAuth flows and expiry
- Excessive data exposure and over-broad responses
- Injection and server-side request forgery
- Mass assignment and unsafe parameter binding
- Rate limiting & resource consumption abuse
- Security misconfiguration and verbose errors
How an engagement runs
Scope. Test. Report.
- 01
Scope
We agree targets, rules of engagement and reporting requirements before any testing starts.
- 02
Test
Harness-driven, AI-accelerated testing across the agreed scope, run on our own local hardware. No denial-of-service or destructive techniques, and no client data leaves for a commercial AI.
- 03
Report
An ISO/IEC 27001:2022-aligned report with prioritised findings, evidence and remediation guidance.
What you receive
A report you can act on and audit against
- Executive summary written for decision-makers
- Every finding rated with a CVSS 3.1 score and clear business impact
- Reproduction steps and evidence for each finding
- Short-term mitigation and long-term fix for every issue
- ISO/IEC 27001:2022 control mapping on each finding
- A remediation tracking & sign-off matrix for your security team
- A retest to verify fixes and update each finding’s status
Ready to scope a api test?
Tell us what needs testing and we’ll propose a scope.