Web & API Application Testing
Manual testing of web applications and APIs, focused on authentication, authorization and business logic — the flaws scanners do not find.
What we test
- Authentication and sessions — login, MFA, password reset, SSO and token handling
- Authorization — horizontal and vertical privilege escalation, tenant isolation, broken object-level authorization
- Business logic — workflows that can be abused in ways the designers did not intend
- Injection and input handling — SQL, command, template and deserialization flaws, SSRF and XSS
- APIs — REST and GraphQL endpoints tested against the OWASP API Security Top 10
Coverage
We test with accounts at each role in your application, and we can review source code alongside dynamic testing when you want deeper coverage in less time.