Scope and authorize
We agree the endpoints, environments and test windows in writing, and note anything that must not be touched.
A test of the APIs behind your products and integrations — REST, GraphQL and the endpoints nobody documented — focused on the authorization and rate-limit failures that make an API far easier to abuse than the app in front of it.
An API has no interface to hide behind. Every endpoint is reachable, every parameter is editable, and the checks a web front end performs for convenience mean nothing to a client the attacker writes themselves.
We test your API as its own attack surface: what each token can reach, what happens when an identifier is changed, and what an automated caller can do before anything stops them.
Typically one to two weeks, depending on how many endpoints and roles are in scope.
We agree the endpoints, environments and test windows in writing, and note anything that must not be touched.
From your specification, traffic capture or the client itself, we enumerate every endpoint — including the ones the documentation forgot.
Every endpoint is exercised with each token type, then with the wrong token, then with no token at all.
We test what an automated caller can extract, trigger or exhaust, and what your logging and rate limits do about it.
Findings arrive with the exact request that proves them, and we retest your fixes once they ship.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
One customer’s token retrieving another customer’s records by id
Fields accepted on update that were never meant to be client-controlled — roles, balances, flags
Tokens that stay valid after logout, password change or user deactivation
Old API versions still live and still vulnerable long after the new one shipped
Endpoints an automated client can call without limit, in cost or in volume
Missing something on this list? Bring it to the call — we scope around what you have.
Find and prove the weaknesses in your web applications before attackers do.
Read moreConfidence that one of your customers can never reach another customer’s data.
Read moreKeep your iOS and Android apps — and the services behind them — out of attackers’ hands.
Read moreMake sure your desktop apps, thick clients, browser extensions and agents don’t open a back door.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.