Scope and authorize
We agree what is in scope, what is off limits, and when we test. You get written authorization and named testers before anything starts.
A hands-on test of your web application — how it authenticates people, what it lets each of them reach and where its logic can be bent — carried out the way a real attacker would, then written up so your engineers can fix what we find.
Scanners find the flaws that look the same everywhere. The ones that matter in your application usually don’t: a role that can read another customer’s records, a checkout step that can be replayed, an admin function that was only ever hidden by the menu. Those take a person who understands what your application is for.
We test every role you give us, from anonymous visitor to administrator, and we test them against each other. When we find something, we prove it — with the request, the response and the data it exposed — so nobody has to take our word for it.
Typically one to two weeks of testing for a mid-sized application, confirmed at scoping.
We agree what is in scope, what is off limits, and when we test. You get written authorization and named testers before anything starts.
We walk the whole application as each role you have given us, so testing covers what the interface exposes and what it does not.
Tooling handles the repetitive sweeps. People decide what to chase, how to chain it and what it would actually cost you.
Each finding is validated and evidenced, and where issues combine into something worse, we show that too — no false alarms forwarded to your team.
You get the technical report, an executive summary, a walkthrough with the testers, and a retest to confirm your fixes worked.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
One role reading or changing another role’s data
Endpoints that enforce nothing because the UI never offers the button
Checkout, quota or approval steps that can be replayed or reordered
Stored cross-site scripting that fires in an administrator’s browser
Keys and internal URLs shipped in the client-side bundle
Missing something on this list? Bring it to the call — we scope around what you have.
Keep the APIs that connect your products, partners and data from becoming the way in.
Read moreConfidence that one of your customers can never reach another customer’s data.
Read moreKeep your iOS and Android apps — and the services behind them — out of attackers’ hands.
Read moreMake sure your desktop apps, thick clients, browser extensions and agents don’t open a back door.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.