Skip to content

Security guides

Understand the boundary. Test it. Keep the evidence.

Practical guides to application security checks, what a result establishes, and which limits belong in the report. Choose a topic that matches the decision you need to make.

Choose the assessment you need.

Preparing a test? Start with scope and inventory. Investigating a candidate? Use the relevant API, browser, or identity guide to identify controls and collect narrowly scoped evidence. Reviewing a result? Read the reporting and retesting guides before treating a finding count as assurance.

Each guide includes a direct answer, specific assessment steps, limitations, FAQs, and links to primary technical sources. Active checks belong on targets you are authorized to assess, using the owner's intended policy and dedicated test fixtures.

API security

Web security

Identity and access

Testing workflow

Compare coverage before choosing a tool.

Different approaches can provide different evidence. Compare the methods, scope, roles, and reporting you need, or discuss a focused assessment with the team.