Penetration testing

Web application penetration testing

We test web applications the way a determined attacker would, across authentication, access control, injection and business logic.

What we test

Where we look

Tested black-box or with credentials you provide, so we cover both the anonymous attacker and the malicious user.

  • Authentication & session management — login, multi-factor, session handling and fixation
  • Access control — horizontal and vertical privilege escalation, insecure direct object references
  • Injection — SQL, command, template and related classes
  • Business-logic flaws that automated scanners miss
  • Sensitive data & error exposure — debug modes, stack traces and leaked internals
  • Security misconfiguration across the application and its stack
  • File upload, SSRF and request-forgery issues
  • Client-side issues — cross-site scripting and related flaws

How an engagement runs

Scope. Test. Report.

  1. 01

    Scope

    We agree targets, rules of engagement and reporting requirements before any testing starts.

  2. 02

    Test

    Harness-driven, AI-accelerated testing across the agreed scope, run on our own local hardware. No denial-of-service or destructive techniques, and no client data leaves for a commercial AI.

  3. 03

    Report

    An ISO/IEC 27001:2022-aligned report with prioritised findings, evidence and remediation guidance.

What you receive

A report you can act on and audit against

  • Executive summary written for decision-makers
  • Every finding rated with a CVSS 3.1 score and clear business impact
  • Reproduction steps and evidence for each finding
  • Short-term mitigation and long-term fix for every issue
  • ISO/IEC 27001:2022 control mapping on each finding
  • A remediation tracking & sign-off matrix for your security team
  • A retest to verify fixes and update each finding’s status

Ready to scope a web application test?

Tell us what needs testing and we’ll propose a scope.