Web application and API penetration testing
I run penetration tests (pentests) of web applications and APIs — the outcome should be useful: realistic attack vectors, clear risks and concrete remediation recommendations. Coverage typically includes auth and sessions, JWT/OAuth, IDOR, injection, XSS, SSRF, file upload and business-logic flaws.
Project kickoff
- 1Defining scope, test environment and rules of engagement (black/grey box)
- 2Recon and manual testing plus tooling, following OWASP methodology
- 3Verifying findings and assessing business risk
- 4Executive + Technical report with priorities and remediation recommendations
I handle design and delivery directly — with contact through analysis, delivery and further development.
Who it is for
- Companies before a major release or entering the enterprise market
- Teams after a migration, an auth refactor or a major API change
- SaaS startups that need to prove security to clients and investors
- Organisations after an incident — verifying that gaps were actually fixed
Problems I solve
- No certainty the application will withstand a real attack before launch
- A previous automated scan produced hundreds of alerts with no priorities
- A B2B client requires a pentest or security report in an RFP
- Many recommendations after an audit, but no verification that fixes actually work
Scope of work
How collaboration works
- Defining scope, test environment and rules of engagement (black/grey box)
- Recon and manual testing plus tooling, following OWASP methodology
- Verifying findings and assessing business risk
- Executive + Technical report with priorities and remediation recommendations
- Walkthrough of results and remediation support (optional retest)
What you get
- A report with a management summary and technical detail
- A vulnerability list with priorities (critical / high / medium / low)
- Concrete remediation steps — not just "update the library"
- Material for conversations with the dev team, an auditor or an enterprise client
FAQ
How does a pentest differ from a vulnerability scanner?
A scanner detects known signatures and often generates noise. A pentest is manual verification, attack chains and business context — the report tells you what genuinely threatens the application.
How long does a penetration test take?
A typical web/API pentest for a single application takes 1–2 weeks, depending on scope, the number of user roles and environments (stage/prod).
Does a pentest break production data?
Testing runs against an agreed environment. For production we apply limits and testing windows so the business is not disrupted.
Do I need an audit before a pentest?
Not always. A pentest checks technical attack vectors. An IT audit has a broader scope (policies, processes, infrastructure). I often combine both, depending on what the company needs.
Is the report understandable for management?
Yes — the report includes an executive summary with business risks plus a technical section for the dev team.
Do you offer a retest after fixes?
Yes, a retest is a separate, shorter stage that verifies whether reported gaps were successfully closed.
Related services and articles
Ready to discuss scope?
Write briefly about the goal, audience and materials you already have. I will reply with a proposed next step.