Skip to content
← All services

Penetration testing service

Web Application Penetration Test

Manual testing of an authenticated web application against the OWASP ASVS, looking for the logic and access-control flaws that scanners do not find.

What the test covers

  • Authentication, session handling and password reset flows
  • Authorisation testing across every role, including horizontal and vertical privilege escalation
  • Business logic abuse — workflow bypass, race conditions, price and quantity tampering
  • Injection classes: SQL, NoSQL, command, template and deserialisation
  • Server-side request forgery and file upload handling
  • Client-side issues: XSS, CSRF, clickjacking, DOM sinks
  • Configuration and header review against the deployed environment

Deliverables

  • Executive summary written for a non-technical reader
  • CVSS-scored findings with reproduction steps and evidence
  • Prioritised remediation roadmap
  • Technical annexure of everything tested, including what came back clean
  • One retest round with a signed closure letter

Out of scope

  • Denial-of-service and volumetric load testing
  • Social engineering of your staff, unless separately agreed in writing
  • Physical security
  • Third-party services you do not own or control