Web application penetration testing

We test your web application and its API the way an attacker would. You get findings ranked by severity, guidance on fixing each one, and a retest that confirms the fix worked.

Web apps and APIsReport with fix guidanceRetest included3D illustration of a shield with a magnifying glass representing penetration testing
What you get

What a penetration test gives you

Flaws a scanner won't find

A scanner spots an outdated library. A person finds out that changing a number in the URL shows you another company's invoice.

Testing the API, not just the screens

We test endpoints directly. A button the interface hides won't stop an attacker if the server doesn't check permissions.

Findings ranked by severity

Every finding comes with its impact, severity and steps to reproduce it. You know what to fix right away and what can wait.

A report for developers and management

Developers get the technical details and fix guidance, management a clear summary of the risks.

Retest included

After the fix, we run the test again. A finding is closed only once we've confirmed the fix really worked.

Testers who build apps themselves

We develop applications, so we can help with the fix in the code, not just describe the problem.

Why it matters

When a penetration test makes sense

Before launching a new application, after a major change, when you take over an app from another vendor, or when you need to prove its security to a customer, an auditor or for NIS2. In nine out of ten applications we test, we find a critical or high-severity vulnerability, even in those built by professional vendors.

We'll test your application, whoever built it.

How a penetration test works

1. Scope and reconnaissance

We agree on what we're testing: the application, the API, user roles and the environment. Then we map everything the application exposes from the outside.

2. Testing and impact verification

We combine automated tools with manual testing based on the OWASP methodology. For every flaw, we verify what an attacker could actually do with it.

3. Report and retest

We hand over the findings ranked by severity, with fix guidance, and go through them with your team. Once they're fixed, we run a retest.

FAQ

What companies ask us

How much does a penetration test cost?
Testing a web application starts at 40,000 CZK excluding VAT. The price goes up mainly with the number of user roles and API endpoints, more complex authentication, and the scope you want covered. A retest after the fix is included. After an initial consultation, you'll get a fixed quote.
How long does a test take?
We can test a smaller application in a few working days; a larger system with many roles and an extensive API takes longer. We agree on the dates in advance so the test doesn't clash with a new release.
Do you test in production?
Preferably in a test environment that mirrors production. We only test in production by agreement, at an agreed time, and without any checks that could disrupt your operations.
What do I get at the end?
A report with findings ranked by severity. Each one includes its impact, steps to reproduce it and a suggested fix. We walk through the findings with your team and run a retest once they're fixed.
How often should an application be tested?
After every major change and at least once a year. If you fall under NIS2, regular testing helps you show that your security measures actually work.
Black box, grey box or white box?
Grey box finds the most: the tester gets access to each role and sees the application the way your users do. Black box simulates an outside attacker with no access, while white box adds a look at the source code. We'll recommend an approach based on what you want to verify.
Contact

Let's get your business moving

Want to start a project with us or have questions? Send us a message, give us a call or book an online meeting!