Web & SaaS
Penetration testing for Web & SaaS applications
A human-led application test focused on your system's permission model, authentication flows and business logic.
Who this test is for
Built for development teams and technology leaders running a business application who want a real picture of their security before a customer review, a release or a significant change.
Multi-tenant SaaS products
Systems where multiple customers share infrastructure, and isolation between them is a critical requirement.
Customer portals and personal areas
Systems that show personal data, documents or financial information to signed-in users.
Internal business applications
Management systems with many roles, where a wrong permission grants too much power.
What actually gets tested
Coverage is tailored to the agreed scope. These are the core areas examined in an application test.
- Access control between users and roles, including access to another account's data
- Authentication flows, password reset and session management
- Input validation and injection attempts in the application's context
- Business logic: pricing, action permissions, invalid process states
- File uploads and handling of user-supplied files
- Configuration, security headers and unnecessary information exposure
Coverage is set by the scope agreed in advance. No dangerous exploitation and no scanning of systems not approved in writing.
Professional guide to Web testing methodology based on OWASP WSTG →
What we need from you to get started
- The address of the environment under test, and what's out of scope
- Test accounts for every relevant permission level
- API documentation or sample requests, if available
- A technical contact for questions during the test
- Written authorization from the party authorized to approve the test
Access details and passwords are not sent through the website form, but through a coordinated channel after we're in touch.
What you receive at the end
- A findings report with an executive summary
- Severity, business impact and evidence for every finding
- Prioritized remediation guidance for the development team
- A review call to clarify findings
- Retest according to the agreed scope
Application testing FAQ
Can the test affect system availability?
How is this different from an API test?
Do you also test infrastructure or networks?
Let's understand what needs testing in your application
Send your details and we'll get back to you to define a precise scope.