Web application and API penetration testing

I run penetration tests (pentests) of web applications and APIs — the outcome should be useful: realistic attack vectors, clear risks and concrete remediation recommendations. Coverage typically includes auth and sessions, JWT/OAuth, IDOR, injection, XSS, SSRF, file upload and business-logic flaws.

Project kickoff

  1. 1Defining scope, test environment and rules of engagement (black/grey box)
  2. 2Recon and manual testing plus tooling, following OWASP methodology
  3. 3Verifying findings and assessing business risk
  4. 4Executive + Technical report with priorities and remediation recommendations

We handle design and delivery directly — with contact through analysis, delivery and further development.

Who it is for

  • Companies before a major release or entering the enterprise market
  • Teams after a migration, an auth refactor or a major API change
  • SaaS startups that need to prove security to clients and investors
  • Organisations after an incident — verifying that gaps were actually fixed

Problems we solve

  • No certainty the application will withstand a real attack before launch
  • A previous automated scan produced hundreds of alerts with no priorities
  • A B2B client requires a pentest or security report in an RFP
  • Many recommendations after an audit, but no verification that fixes actually work

Scope of work

Testing of web applications and REST/GraphQL APIs
Auth, sessions, JWT, OAuth and access control (IDOR, privilege escalation)
Configuration: security headers, CORS, rate limiting, CSP
Injection (SQL, NoSQL, command), XSS, SSRF, file upload, business logic flaws
Optional: retest after fixes are deployed

How collaboration works

  1. Defining scope, test environment and rules of engagement (black/grey box)
  2. Recon and manual testing plus tooling, following OWASP methodology
  3. Verifying findings and assessing business risk
  4. Executive + Technical report with priorities and remediation recommendations
  5. Walkthrough of results and remediation support (optional retest)

What you get

  • A report with a management summary and technical detail
  • A vulnerability list with priorities (critical / high / medium / low)
  • Concrete remediation steps — not just "update the library"
  • Material for conversations with the dev team, an auditor or an enterprise client

FAQ

How does a pentest differ from a vulnerability scanner?

A scanner detects known signatures and often generates noise. A pentest is manual verification, attack chains and business context — the report tells you what genuinely threatens the application.

How long does a penetration test take?

A typical web/API pentest for a single application takes 1–2 weeks, depending on scope, the number of user roles and environments (stage/prod).

Does a pentest break production data?

Testing runs against an agreed environment. For production we apply limits and testing windows so the business is not disrupted.

Do I need an audit before a pentest?

Not always. A pentest checks technical attack vectors. An IT audit has a broader scope (policies, processes, infrastructure). I often combine both, depending on what the company needs.

Is the report understandable for management?

Yes — the report includes an executive summary with business risks plus a technical section for the dev team.

Do you offer a retest after fixes?

Yes, a retest is a separate, shorter stage that verifies whether reported gaps were successfully closed.

Related services and articles

Ready to discuss scope?

Write briefly about the goal, audience and materials you already have. We will reply with a proposed next step.