Penetration Testing (Web, API, Mobile)
Manual, adversary-style testing of applications and their business logic, with a retest included.
A penetration test answers a simple question: can someone break this, and what happens if they do? We test web applications, APIs and mobile apps by hand, following the paths a motivated attacker would take, including the logic flaws, privilege escalations and chained weaknesses that automated tools miss.
The report gives each finding a severity, an exploit path, a business impact and a fix. After remediation we retest and confirm it in writing.
- Every test is manual with tooling in support, so business logic and chained issues are found.
- Findings are written for the developer who fixes them, with reproduction steps and code-level advice.
- The retest is included in every engagement, not sold separately.
- A bank, insurer or payments business with customer-facing applications under regulatory scrutiny.
- An airline or retailer whose booking and checkout APIs carry personal and payment data at volume.
- A group whose customers require a current test report before every contract renewal.
- The last test was a scan that produced a long list and no exploit paths.
- A major release is due and security review is a checkbox at the end.
- Customer or auditor questionnaires ask for a test letter you do not have.
- New APIs and mobile clients have shipped since the application was last tested.
What is included.
- 01
Web application testing
Authentication, authorisation, injection, session handling and business logic across all user roles.
- 02
API testing
REST and GraphQL endpoints tested for broken access control, data exposure and abuse.
- 03
Mobile application testing
iOS and Android clients, local storage, transport security and back-end interaction.
- 04
Secure code review
Targeted review of critical code paths to find what black-box testing can't reach.
- 05
Reporting and retest
Full report, findings review call and a retest with confirmation letter.
Four steps, no surprises.
- 01
Scope
Targets, roles, environments and rules of engagement agreed in writing.
- 02
Recon and map
Application surface, endpoints and trust boundaries mapped.
- 03
Exploit
Manual testing with proof of impact, stopping at the agreed limits.
- 04
Report and retest
Report, review call, remediation window and retest.
From first meeting to steady state.
- 01Week 1
Scope
Targets, roles, environments and rules of engagement agreed in writing.
- 02Weeks 2 to 3
Test
Manual testing across roles with proof of impact, stopping at the agreed limits.
- 03Week 4
Report and review
Full report, executive summary and a findings review with your developers.
- 04Within the remediation window
Retest
Fixes verified and a confirmation letter issued for customers and auditors.
- Critical and high findings open, tracked from report to retest.
- Time from report to confirmed remediation.
- Findings per release over time as secure development takes hold.
- Coverage of applications, APIs and roles tested against the estate.
- Lead penetration tester
- Application security consultant
- Mobile security specialist
- Engagement manager
- Findings report with severity, exploit paths and remediation.
- Executive summary.
- Findings review session.
- Retest report.
- Confirmation letter for customers and auditors.
Penetration tests are fixed scope, agreed after a scoping call. A single application typically takes one to two weeks of testing with the report delivered within a week after. The retest is scheduled within three months of the report. Organisations with continuous release cycles can move to an annual testing retainer.
AI/LLM Security Assessment
Prompt injection, data leakage and model abuse testing for AI features, assistants and agents.
CybersecurityNetwork & Cloud Security Assessment
External and internal network tests and AWS, Azure and Google Cloud configuration reviews.
Web, Webshop & App DevelopmentWeb Applications & SaaS Platforms
Custom portals, dashboards and multi-tenant SaaS with authentication, billing and admin built in.
Penetration Testing (Web, API, Mobile), in plain terms.
A scan finds known issues automatically. A penetration test has a person try to break the application, including logic and chained flaws. We use both, but only the second counts as a test.
Either, depending on risk. Staging environments that match production are preferred for intrusive testing, with production checks where behaviour differs.
For a thorough test, yes. Authenticated testing across roles is where most serious issues are found.
OWASP testing guides, the OWASP Top 10 and API Top 10, and the relevant mobile standards, with severity rated using CVSS.