Web application penetration testing
We test your web application and its API the way an attacker would. You get findings ranked by severity, guidance on fixing each one, and a retest that confirms the fix worked.

What a penetration test gives you
Flaws a scanner won't find
A scanner spots an outdated library. A person finds out that changing a number in the URL shows you another company's invoice.
Testing the API, not just the screens
We test endpoints directly. A button the interface hides won't stop an attacker if the server doesn't check permissions.
Findings ranked by severity
Every finding comes with its impact, severity and steps to reproduce it. You know what to fix right away and what can wait.
A report for developers and management
Developers get the technical details and fix guidance, management a clear summary of the risks.
Retest included
After the fix, we run the test again. A finding is closed only once we've confirmed the fix really worked.
Testers who build apps themselves
We develop applications, so we can help with the fix in the code, not just describe the problem.
When a penetration test makes sense
Before launching a new application, after a major change, when you take over an app from another vendor, or when you need to prove its security to a customer, an auditor or for NIS2. In nine out of ten applications we test, we find a critical or high-severity vulnerability, even in those built by professional vendors.
We'll test your application, whoever built it.
/api/invoices/10423How a penetration test works
- Applicationapp.company.com
- API42 endpoints
- Rolesadmin, accountant, customer
- Environmentstaging
1. Scope and reconnaissance
We agree on what we're testing: the application, the API, user roles and the environment. Then we map everything the application exposes from the outside.
SQL injectionblockedXSSblockedChanging the ID in the URLfindingPassword guessingblocked
2. Testing and impact verification
We combine automated tools with manual testing based on the OWASP methodology. For every flaw, we verify what an attacker could actually do with it.
- Critical1
- High2
- Medium3
3. Report and retest
We hand over the findings ranked by severity, with fix guidance, and go through them with your team. Once they're fixed, we run a retest.
What companies ask us
How much does a penetration test cost?
How long does a test take?
Do you test in production?
What do I get at the end?
How often should an application be tested?
Black box, grey box or white box?
Let's get your business moving
Want to start a project with us or have questions? Send us a message, give us a call or book an online meeting!
