Web & API Security
Manual penetration testing focused on authentication, authorization, sessions, APIs and business logic. These are the issues automated scanning consistently misses.
- Authentication & account lifecycle. Registration, email verification and pre-registration collisions. Password reset token generation, binding, reuse and expiry.
- Authorization & tenancy. Horizontal access: reading and writing other users' objects. Vertical access: privilege escalation between roles.
- APIs. Access control on every endpoint, including undocumented and legacy versions. Excessive data exposure and over-broad serializers.
- Business logic. Checkout and pricing manipulation. Quantity, discount, credit and refund abuse.
- Application foundations. OWASP Top 10 coverage across the tested scope. Injection, SSRF, insecure deserialization and file upload.
- SaaS teams preparing for launch or a larger customer's security review
- Fintech and e-commerce platforms where money and account state change hands
- B2B products with roles, permissions and multiple tenants
- Teams that have run scanners and want to know what those scanners cannot see
- Confirmed scope and written, authorized rules of engagement
- Manual testing supported by appropriate tooling and evidence collection
- A report with severity, business impact, reproduction steps and evidence
- Remediation guidance specific to your code and architecture