Opulence.
Cybersecurity

Penetration Testing (Web, API, Mobile)

Manual, adversary-style testing of applications and their business logic, with a retest included.

A penetration test answers a simple question: can someone break this, and what happens if they do? We test web applications, APIs and mobile apps by hand, following the paths a motivated attacker would take, including the logic flaws, privilege escalations and chained weaknesses that automated tools miss.

The report gives each finding a severity, an exploit path, a business impact and a fix. After remediation we retest and confirm it in writing.

How we're different
  • Every test is manual with tooling in support, so business logic and chained issues are found.
  • Findings are written for the developer who fixes them, with reproduction steps and code-level advice.
  • The retest is included in every engagement, not sold separately.
Who this is for
  • A bank, insurer or payments business with customer-facing applications under regulatory scrutiny.
  • An airline or retailer whose booking and checkout APIs carry personal and payment data at volume.
  • A group whose customers require a current test report before every contract renewal.
Signals you need this now
  • The last test was a scan that produced a long list and no exploit paths.
  • A major release is due and security review is a checkbox at the end.
  • Customer or auditor questionnaires ask for a test letter you do not have.
  • New APIs and mobile clients have shipped since the application was last tested.
Scope of work

What is included.

  1. 01

    Web application testing

    Authentication, authorisation, injection, session handling and business logic across all user roles.

  2. 02

    API testing

    REST and GraphQL endpoints tested for broken access control, data exposure and abuse.

  3. 03

    Mobile application testing

    iOS and Android clients, local storage, transport security and back-end interaction.

  4. 04

    Secure code review

    Targeted review of critical code paths to find what black-box testing can't reach.

  5. 05

    Reporting and retest

    Full report, findings review call and a retest with confirmation letter.

Method

Four steps, no surprises.

  1. 01

    Scope

    Targets, roles, environments and rules of engagement agreed in writing.

  2. 02

    Recon and map

    Application surface, endpoints and trust boundaries mapped.

  3. 03

    Exploit

    Manual testing with proof of impact, stopping at the agreed limits.

  4. 04

    Report and retest

    Report, review call, remediation window and retest.

How the engagement runs

From first meeting to steady state.

  1. 01Week 1

    Scope

    Targets, roles, environments and rules of engagement agreed in writing.

  2. 02Weeks 2 to 3

    Test

    Manual testing across roles with proof of impact, stopping at the agreed limits.

  3. 03Week 4

    Report and review

    Full report, executive summary and a findings review with your developers.

  4. 04Within the remediation window

    Retest

    Fixes verified and a confirmation letter issued for customers and auditors.

What we measure
  • Critical and high findings open, tracked from report to retest.
  • Time from report to confirmed remediation.
  • Findings per release over time as secure development takes hold.
  • Coverage of applications, APIs and roles tested against the estate.
Who is on the engagement
  • Lead penetration tester
  • Application security consultant
  • Mobile security specialist
  • Engagement manager
Deliverables
  • Findings report with severity, exploit paths and remediation.
  • Executive summary.
  • Findings review session.
  • Retest report.
  • Confirmation letter for customers and auditors.
Engagement terms

Penetration tests are fixed scope, agreed after a scoping call. A single application typically takes one to two weeks of testing with the report delivered within a week after. The retest is scheduled within three months of the report. Organisations with continuous release cycles can move to an annual testing retainer.

FAQ

Penetration Testing (Web, API, Mobile), in plain terms.

A scan finds known issues automatically. A penetration test has a person try to break the application, including logic and chained flaws. We use both, but only the second counts as a test.

Either, depending on risk. Staging environments that match production are preferred for intrusive testing, with production checks where behaviour differs.

For a thorough test, yes. Authenticated testing across roles is where most serious issues are found.

OWASP testing guides, the OWASP Top 10 and API Top 10, and the relevant mobile standards, with severity rated using CVSS.

Next step

Ready to talk about penetration testing (web, api, mobile)?