Skip to content
← All services

Penetration testing service

API Penetration Test

REST and GraphQL testing against the OWASP API Top 10, with particular attention to object-level authorisation — the flaw class that most often survives a web app test.

What the test covers

  • Broken object-level and function-level authorisation across every endpoint
  • Authentication and token handling, including JWT implementation review
  • Mass assignment and excessive data exposure
  • GraphQL introspection, query depth and batching abuse
  • Rate limiting and resource consumption controls
  • Input validation and injection across all parameters

Deliverables

  • Executive summary
  • CVSS-scored findings with working requests and responses as evidence
  • Endpoint-by-endpoint coverage table
  • Prioritised remediation roadmap
  • One retest round with a signed closure letter

Out of scope

  • Load and stress testing
  • Upstream services outside your control