Manual testing built around how your application actually works
Scanners recognise patterns. They do not understand that a viewer should never approve an invoice, that a coupon should not stack twice, or that a tenant identifier in a request body is a trust boundary. Every engagement starts by modelling your roles, workflows and money paths, then testing them the way a motivated attacker would.
- SaaS teams preparing for launch or a larger customer's security review
- Fintech and e-commerce platforms where money and account state change hands
- B2B products with roles, permissions and multiple tenants
- Teams that have run scanners and want to know what those scanners cannot see
- A clear answer to “can this be abused?” before a customer or attacker finds out
- Findings a developer can act on without a follow-up meeting
- Documented verification you can share with customers and partners
What the work covers
Final coverage is confirmed during scoping. Everything below is in the standard toolkit for this service.
Authentication & account lifecycle
- Registration, email verification and pre-registration collisions
- Password reset token generation, binding, reuse and expiry
- OTP and one-time code strength, replay, flooding and brute force
- Session issuance, fixation, termination and post-reset invalidation
- Email and phone change flows, re-authentication and notification
- Account recovery and lockout behaviour
Authorization & tenancy
- Horizontal access: reading and writing other users' objects
- Vertical access: privilege escalation between roles
- Multi-tenant isolation across every data path, not just the UI
- Role-based access control consistency between web and API
- Team invitations, seat limits and permission inheritance
APIs
- Access control on every endpoint, including undocumented and legacy versions
- Excessive data exposure and over-broad serializers
- Mass assignment and unexpected parameter handling
- Input validation, injection surfaces and file handling
- Rate limiting, quota enforcement and abuse resistance
Business logic
- Checkout and pricing manipulation
- Quantity, discount, credit and refund abuse
- Workflow sequence bypass and skipped verification steps
- Plan, trial and usage-limit evasion
- State transitions that were never drawn on the diagram
Application foundations
- OWASP Top 10 coverage across the tested scope
- Injection, SSRF, insecure deserialization and file upload
- Security misconfiguration and unsafe defaults
- Sensitive data exposure in responses, logs and errors
What you actually receive
Every engagement is documented. If it is not written down, it did not happen.
- Confirmed scope and written, authorized rules of engagement
- Manual testing supported by appropriate tooling and evidence collection
- A report with severity, business impact, reproduction steps and evidence
- Remediation guidance specific to your code and architecture
- A results debrief call to walk the team through the findings
- One standard retest of reported findings, with verification recorded
Web & API Security
Manual security testing built around how the application and its business workflows actually operate. Prices are starting points, scope is confirmed in writing before anything begins.
| Service | Best for | Price |
|---|---|---|
| Focused Security Review | One critical feature or workflow | From $250 |
| Small Web Application Pentest | Small app with limited functionality | From $500 |
| Standard Web Application Pentest | Broader application coverage | From $700 |
| Web Application + API Pentest | Web interface and supporting APIs | From $1,000 |
| Multi-Role / Multi-Tenant SaaS Pentest | Roles, permissions and tenant isolation | From $1,400 |
| Security Hardening & Configuration Review | An existing site, server or platform reviewed against its configuration | From $200 |
| Additional Retest | Extra or delayed verification cycle | From $200 |
- Testing requires written authorization and agreed rules of engagement before it begins.
- The focused review covers one agreed feature or workflow and is not presented as a complete application penetration test.
- Testing is normally performed against a staging environment that mirrors production. Where production testing is required, it is scheduled and scoped to avoid disruption.
- Client data and findings are treated as confidential and are not disclosed or reused without written permission.
Web & API Security: asked and answered
What exactly will be tested?
Scope is confirmed in writing before anything starts: the applications, endpoints, roles and workflows in scope, the accounts provided, and anything explicitly excluded. You receive that document before testing begins, and it is reproduced in the report so a future reader knows how much coverage the assessment actually represents.
How long does an engagement take?
It depends on the size of the application, how many roles exist and whether APIs are in scope. Multi-role and multi-tenant platforms take longer, because the findings that matter are in the combinations. You get a specific timeline together with the quotation, before you commit to anything.
Will testing affect our production system?
Testing is normally performed against staging. Where production is unavoidable, we agree the window, avoid destructive techniques, keep volumes low, and stay reachable throughout so anything unexpected can be stopped immediately.
What access do you need?
At minimum, credentials for each role in scope, ideally two accounts per role so authorization between peers can be tested properly. Documentation, an API collection and a short walkthrough of the product speed things up considerably and usually improve what the engagement finds.
How is this different from running a scanner?
A scanner tells you whether you have the common, pattern-matchable problems. Manual testing tells you whether your specific application can be abused: the authorization gaps, account-lifecycle weaknesses and business-logic flaws that look like valid traffic. Both are useful; they answer different questions.
Is retesting included?
One standard retest of reported findings is included in full penetration test packages. The report records what was retested, when, and whether the fix held. Additional or delayed verification cycles can be booked separately.
Ready to scope web & api security?
Send the details: what the platform is, which roles exist, which environment we can use and when you need it done. You get a written scope and a fixed quotation.