We examine agreed application boundaries, including interfaces, APIs, authentication and user input handling. Source-code access enables additional implementation and dependency review.
Findings are verified and documented with reproduction conditions and potential impact. Fixes are retested; the report describes the assessed version and does not guarantee the security of future changes.
Application security testing
Who it is for
- Teams launching or changing applications that process sensitive data
Application security testing
Challenges we address
- Access control and input handling defects may expose information
Application security testing
What is included
- Role, session and API checks
- Input, dependency and configuration analysis
- Finding validation and remediation retesting
Application security testing
What you receive
- Prioritised vulnerability report
- Developer recommendations and retest results
How we work
- 01
Discovery and scope
We assess the current environment, requirements and constraints. Priorities include: Access control and input handling defects may expose information. We agree on scope and acceptance criteria.
- 02
Design and implementation
We design the solution and carry out agreed activities: Role, session and API checks; Input, dependency and configuration analysis; Finding validation and remediation retesting. Changes are checked before entering the production environment.
- 03
Validation and handover
We validate agreed scenarios, record limitations and hand over documentation. Project timing follows discovery; support hours and response targets are defined in a separate agreement.
How pricing works
Estimates depend on features, roles, APIs, code access and the agreed assessment depth.
Get a consultationCommon questions
Is source code required?
Testing is possible without it, but code access enables investigation of additional issue classes. The approach and its limitations are agreed before work begins.