
// Services / Web Applications
Web Application Testing
Your customer portal, internal tools and APIs handle your most sensitive data. We test them by hand — the way an attacker would — to find the flaws automated scanners miss.
// Coverage
Aligned to the OWASP Testing Guide.
Every test covers the OWASP Top 10 and goes beyond it — with a focus on how your application actually works and where its logic can be abused.
Authentication & sessions
Login flows, MFA, password reset, session handling, SSO and token security.
Access control
Horizontal and vertical privilege escalation, insecure direct object references and multi-tenant isolation.
Injection & input handling
SQL, command and template injection, cross-site scripting, SSRF and file upload abuse.
Business logic
Workflows, pricing, approvals and limits that can be bypassed or misused — invisible to scanners.
APIs
REST and GraphQL endpoints, authorization on every route, mass assignment and excessive data exposure.
Configuration
Security headers, TLS, CORS, error handling, exposed admin interfaces and third-party components.
// How it works
Authenticated, manual and thorough.
We test with accounts at each role your application supports, so we can verify that users only see and do what they’re supposed to. Automated tools help with coverage; the meaningful findings come from manual analysis.
- Testing against staging or production — your choice
- Every finding includes proof-of-concept and fix guidance
- Developer-friendly reporting your team or vendor can act on
- Retest of fixed issues to confirm closure
CS-01AD CS template allows domain escalation (ESC1)CriticalCS-02Kerberoastable service account on path to DACriticalCS-03SMB signing not required — NTLM relay possibleHighCS-04VPN appliance running vulnerable firmwareHighCS-05Stored XSS in customer portal commentsMediumCS-06Verbose server errors disclose stack tracesLow// FAQ
Web application testing questions
Our app was built by a third-party vendor. Can you still test it?
Yes — as long as you own or are authorized to test the application. We’ll help you coordinate with the vendor, and our findings are written so their developers can reproduce and fix them.
Should we test in staging or production?
Staging is preferred when it closely matches production, since it allows more aggressive testing. Production testing is also possible with careful coordination and safe techniques.
How long does a web application test take?
It depends on size and complexity — the number of roles, pages and API endpoints. Most small to mid-sized applications take one to two weeks. You’ll get a fixed scope and price up front.
// Next step
Know where you stand before someone else finds out.
Start with a no-obligation scoping call. We’ll talk through your environment, what’s driving the test and the timeline that works for you.