Skip to main content
HPI CYBERApplication Security

Web & SaaS

Penetration testing for Web & SaaS applications

A human-led application test focused on your system's permission model, authentication flows and business logic.

Who this test is for

Built for development teams and technology leaders running a business application who want a real picture of their security before a customer review, a release or a significant change.

Multi-tenant SaaS products

Systems where multiple customers share infrastructure, and isolation between them is a critical requirement.

Customer portals and personal areas

Systems that show personal data, documents or financial information to signed-in users.

Internal business applications

Management systems with many roles, where a wrong permission grants too much power.

What actually gets tested

Coverage is tailored to the agreed scope. These are the core areas examined in an application test.

  • Access control between users and roles, including access to another account's data
  • Authentication flows, password reset and session management
  • Input validation and injection attempts in the application's context
  • Business logic: pricing, action permissions, invalid process states
  • File uploads and handling of user-supplied files
  • Configuration, security headers and unnecessary information exposure

Coverage is set by the scope agreed in advance. No dangerous exploitation and no scanning of systems not approved in writing.

Professional guide to Web testing methodology based on OWASP WSTG →

What we need from you to get started

  • The address of the environment under test, and what's out of scope
  • Test accounts for every relevant permission level
  • API documentation or sample requests, if available
  • A technical contact for questions during the test
  • Written authorization from the party authorized to approve the test

Access details and passwords are not sent through the website form, but through a coordinated channel after we're in touch.

What you receive at the end

  • A findings report with an executive summary
  • Severity, business impact and evidence for every finding
  • Prioritized remediation guidance for the development team
  • A review call to clarify findings
  • Retest according to the agreed scope

Application testing FAQ

Can the test affect system availability?
A coordinated application test significantly reduces the risk, including through an approved environment, a defined time window and a stop contact. However, zero impact can't be guaranteed, which is why coordination is defined in advance.
How is this different from an API test?
An application test focuses on the user interface and product flows, including the layer behind them. An API test focuses on the endpoints themselves, object- and function-level authorization and data exposure. Both can be combined in one scope.
Do you also test infrastructure or networks?
No. This service focuses on Web applications, SaaS platforms and APIs. Infrastructure, network or mobile testing is not part of this offering.

Let's understand what needs testing in your application

Send your details and we'll get back to you to define a precise scope.

Request test scoping

Please don't send passwords, API keys, access credentials or confidential information in this form.

Get a Pentest Quote