Skip to content

Expert-led service

Web application penetration testing.

We test your web app the way an attacker would: every role, every workflow, every input — looking for the flaw that turns an ordinary account into access it should never have.

What we test

Scope, agreed in writing.

  • Authentication

    Login, password reset, MFA and account recovery flows.

  • Access control

    Horizontal and vertical privilege checks across every role (IDOR/BOLA).

  • Injection and XSS

    SQL, command, template and client-side injection, verified by hand.

  • Sessions

    Token handling, fixation, expiry, logout and cookie security.

  • Business logic

    Price and quantity tampering, workflow bypasses, race conditions — agreed in scope.

  • Configuration

    Headers, CORS, TLS, exposed files and debug surfaces.

How we work

Methodical, and never destructive without agreement.

  1. 01Map the application: roles, workflows, APIs behind the UI.
  2. 02Test each role against each other role's data and actions.
  3. 03Probe inputs by hand, confirming every finding before it's reported.
  4. 04Chain lower-severity issues where they combine into something worse.

What you receive

  • Findings with reproduction steps, evidence and CVSS severity
  • Specific fixes for your stack
  • Executive summary
  • Retest and written confirmation

Manual testing or MyPentest?

MyPentest covers much of the configuration, injection and access-control surface automatically — including signed-in tests with your test accounts. Run it free on every release.

Choose a manual test for business logic, complex roles, payments, or when you need evidence for a customer or auditor.

Automated vs manual penetration testing

FAQ

Questions, answered straight.

How long does an engagement take?

Most engagements run 5–12 testing days depending on scope, with the report delivered within 5 business days of testing finishing. Exact dates are agreed in the scoping document before you commit.

Will testing affect production?

Rules of engagement are agreed in writing before anything starts. We recommend a staging environment; when production testing is required we use non-destructive techniques, throttle traffic and agree testing windows. Denial-of-service testing is never performed without explicit written agreement.

Is retesting included?

Yes. When you've fixed the issues, we retest them and confirm in writing which are closed.

Talk to a tester, not a sales team.

A free 30-minute scoping call, then a fixed quote in writing. Or start with a free automated pentest today.