SERVICE / 01 · APPLICATIONS

Web and API penetration testing

Authentication, business logic, permission control and data exposure. We follow the paths that connect an apparently minor flaw to real impact on your operation.

We do not run a scanner and email you the PDF. A person tests your application by hand, chains what they find and demonstrates how far someone who really wants in can get.

Every finding is prioritised by impact on your business, not by a tool’s generic severity. The retest is included: we do not close until we confirm it is closed.

What we look at

  • Authentication, sessions and account recovery
  • Business logic and cross-role access control
  • REST and GraphQL APIs: object-level authorisation
  • Data exposure and cross-tenant leakage

What you get

  • Manual testing
  • Reproducible evidence
  • Impact prioritisation
  • Retest

Related services

Shall we put this to the test?

We define the scope with you and start with written authorisation.

Request an assessment
KNULL / DATA
DATA / CONTACT

Only what
we need.

This page collects nothing. The request form on the home page stores only what you send it, on the server that hosts this site, with no analytics and no AI model.