Expert-led service
Web application penetration testing.
We test your web app the way an attacker would: every role, every workflow, every input — looking for the flaw that turns an ordinary account into access it should never have.
What we test
Scope, agreed in writing.
Authentication
Login, password reset, MFA and account recovery flows.
Access control
Horizontal and vertical privilege checks across every role (IDOR/BOLA).
Injection and XSS
SQL, command, template and client-side injection, verified by hand.
Sessions
Token handling, fixation, expiry, logout and cookie security.
Business logic
Price and quantity tampering, workflow bypasses, race conditions — agreed in scope.
Configuration
Headers, CORS, TLS, exposed files and debug surfaces.
How we work
Methodical, and never destructive without agreement.
- 01Map the application: roles, workflows, APIs behind the UI.
- 02Test each role against each other role's data and actions.
- 03Probe inputs by hand, confirming every finding before it's reported.
- 04Chain lower-severity issues where they combine into something worse.
What you receive
- Findings with reproduction steps, evidence and CVSS severity
- Specific fixes for your stack
- Executive summary
- Retest and written confirmation
Manual testing or MyPentest?
MyPentest covers much of the configuration, injection and access-control surface automatically — including signed-in tests with your test accounts. Run it free on every release.
Choose a manual test for business logic, complex roles, payments, or when you need evidence for a customer or auditor.
Automated vs manual penetration testingFAQ
Questions, answered straight.
How long does an engagement take?
Most engagements run 5–12 testing days depending on scope, with the report delivered within 5 business days of testing finishing. Exact dates are agreed in the scoping document before you commit.
Will testing affect production?
Rules of engagement are agreed in writing before anything starts. We recommend a staging environment; when production testing is required we use non-destructive techniques, throttle traffic and agree testing windows. Denial-of-service testing is never performed without explicit written agreement.
Is retesting included?
Yes. When you've fixed the issues, we retest them and confirm in writing which are closed.
Talk to a tester, not a sales team.
A free 30-minute scoping call, then a fixed quote in writing. Or start with a free automated pentest today.