Web application and API penetration testing

I run penetration tests (pentests) of web applications and APIs — the outcome should be useful: realistic attack vectors, clear risks and concrete remediation recommendations. Coverage typically includes auth and sessions, JWT/OAuth, IDOR, injection, XSS, SSRF, file upload and business-logic flaws.

Project kickoff

  1. 1Defining scope, test environment and rules of engagement (black/grey box)
  2. 2Recon and manual testing plus tooling, following OWASP methodology
  3. 3Verifying findings and assessing business risk
  4. 4Executive + Technical report with priorities and remediation recommendations

I handle design and delivery directly — with contact through analysis, delivery and further development.

Who it is for

  • Companies before a major release or entering the enterprise market
  • Teams after a migration, an auth refactor or a major API change
  • SaaS startups that need to prove security to clients and investors
  • Organisations after an incident — verifying that gaps were actually fixed

Problems I solve

  • No certainty the application will withstand a real attack before launch
  • A previous automated scan produced hundreds of alerts with no priorities
  • A B2B client requires a pentest or security report in an RFP
  • Many recommendations after an audit, but no verification that fixes actually work

Scope of work

Testing of web applications and REST/GraphQL APIs
Auth, sessions, JWT, OAuth and access control (IDOR, privilege escalation)
Configuration: security headers, CORS, rate limiting, CSP
Injection (SQL, NoSQL, command), XSS, SSRF, file upload, business logic flaws
Optional: retest after fixes are deployed

How collaboration works

  1. Defining scope, test environment and rules of engagement (black/grey box)
  2. Recon and manual testing plus tooling, following OWASP methodology
  3. Verifying findings and assessing business risk
  4. Executive + Technical report with priorities and remediation recommendations
  5. Walkthrough of results and remediation support (optional retest)

What you get

  • A report with a management summary and technical detail
  • A vulnerability list with priorities (critical / high / medium / low)
  • Concrete remediation steps — not just "update the library"
  • Material for conversations with the dev team, an auditor or an enterprise client

FAQ

How does a pentest differ from a vulnerability scanner?

A scanner detects known signatures and often generates noise. A pentest is manual verification, attack chains and business context — the report tells you what genuinely threatens the application.

How long does a penetration test take?

A typical web/API pentest for a single application takes 1–2 weeks, depending on scope, the number of user roles and environments (stage/prod).

Does a pentest break production data?

Testing runs against an agreed environment. For production we apply limits and testing windows so the business is not disrupted.

Do I need an audit before a pentest?

Not always. A pentest checks technical attack vectors. An IT audit has a broader scope (policies, processes, infrastructure). I often combine both, depending on what the company needs.

Is the report understandable for management?

Yes — the report includes an executive summary with business risks plus a technical section for the dev team.

Do you offer a retest after fixes?

Yes, a retest is a separate, shorter stage that verifies whether reported gaps were successfully closed.

Related services and articles

Ready to discuss scope?

Write briefly about the goal, audience and materials you already have. I will reply with a proposed next step.