Web, API and infrastructure pentesting
Manual offensive audit of the assets you expose and the ones that run the business: the application, the API behind it and the network it lives on.
For companies with their own application or client portal, e-commerce and SaaS, or that must evidence an audit to a large client, an insurer or a public tender.
What is included
- Web application: authentication, session, access control, business logic and injection
- REST or GraphQL API: object-level authorisation, rate limits and data exposure
- External and internal infrastructure, Active Directory or cloud, per scope
- Review of the organisation's credentials leaked in public sources
- Technical report with proof of concept and CVSS score, executive summary and prioritised plan
- Verification retest included
What is not included
- Continuous red team or multi-month campaigns, quoted separately
- Full source-code audit, which can be added to the scope
- Attacks with denial-of-service risk, unless expressly authorised
Half of the serious findings we identify are invisible to tools: they are business-logic and permission flaws.