Penetration testing
Web application penetration testing
We test web applications the way a determined attacker would, across authentication, access control, injection and business logic.
What we test
Where we look
Tested black-box or with credentials you provide, so we cover both the anonymous attacker and the malicious user.
- Authentication & session management — login, multi-factor, session handling and fixation
- Access control — horizontal and vertical privilege escalation, insecure direct object references
- Injection — SQL, command, template and related classes
- Business-logic flaws that automated scanners miss
- Sensitive data & error exposure — debug modes, stack traces and leaked internals
- Security misconfiguration across the application and its stack
- File upload, SSRF and request-forgery issues
- Client-side issues — cross-site scripting and related flaws
How an engagement runs
Scope. Test. Report.
- 01
Scope
We agree targets, rules of engagement and reporting requirements before any testing starts.
- 02
Test
Harness-driven, AI-accelerated testing across the agreed scope, run on our own local hardware. No denial-of-service or destructive techniques, and no client data leaves for a commercial AI.
- 03
Report
An ISO/IEC 27001:2022-aligned report with prioritised findings, evidence and remediation guidance.
What you receive
A report you can act on and audit against
- Executive summary written for decision-makers
- Every finding rated with a CVSS 3.1 score and clear business impact
- Reproduction steps and evidence for each finding
- Short-term mitigation and long-term fix for every issue
- ISO/IEC 27001:2022 control mapping on each finding
- A remediation tracking & sign-off matrix for your security team
- A retest to verify fixes and update each finding’s status
Ready to scope a web application test?
Tell us what needs testing and we’ll propose a scope.