Web application penetration testing
Validate the business logic, sessions and access controls behind your application.
Authentication, recovery and session lifecycle · Object and function authorisation across roles

PENETRATION TESTING SERVICES
Find out what an attacker could actually do within your agreed scope. We connect technical weaknesses to business operations, explain the controls that hold and give your teams evidence they can use to fix and retest.
Make release, remediation and risk decisions using demonstrated results, explicit coverage and testable acceptance criteria.
We distinguish a scanner observation from a validated weakness, usable access from network reachability, and demonstrated impact from an untested possibility.
A public application, cloud workload and internal identity system may form one connected attack path. Scope those relationships deliberately, including third-party permissions, business rules and recovery dependencies.
Inside the engagement02 / TESTING SCOPE
Validate the business logic, sessions and access controls behind your application.
Authentication, recovery and session lifecycle · Object and function authorisation across roles
Test object ownership, service permissions and workflow state across API families.
REST, GraphQL and documented integration surfaces · Cross-tenant object access and function permissions
Examine reachable services, trust relationships and privileged access paths.
External and internal service exposure · Directory identities, delegation and privileged groups
Assess the authority exposed by cloud workloads, storage and deployment pipelines.
AWS, Azure or Google Cloud scope agreed per engagement · Workload roles, token exchange and secrets handling
Review mobile clients alongside the APIs and identity services they use.
Android or iOS builds and supported test devices · Local storage, secrets and platform interactions
Validate that a specific fix closes the demonstrated path and preserves authorised use.
Original finding prerequisites and negative cases · Deployed versions and effective configuration

A controlled process.
Evidence at every step.
Define systems, identities, objectives, permissions and operating constraints.
Connect relevant attack scenarios to the services and data you need to protect.
Use written authorisation, agreed environments, synthetic data and named stop authority. Define rate limits, excluded methods, cleanup and escalation before testing. Production activity and supplier systems require explicit permission.
Record actions, responses, effective controls and the limits of access gained.
Prioritise findings, assign ownership and retest agreed acceptance criteria.
A test should inform your security decisions.
A penetration test can support a security programme, customer assurance or contractual requirement. The required scope, frequency, independence and evidence depend on the applicable standard and agreement. A generic test is not a compliance certificate, and statutory DORA TLPT is a separate engagement with additional requirements.
INSIDE THE SAMPLE REPORT
The fictional Meridian Group AG case contains 68 pages, three connected scenarios, twelve findings and individual treatment plans.
Preview the sample reportScoped scans, WAF responses, shell context and downstream API results.
Separate unaided access, approved assistance, blocked routes and unperformed actions.
Owners, immediate safeguards, durable fixes and completed or pending retests.
04 / INSIGHTS & PERSPECTIVES

Separate a defined technical test from advanced testing obligations that apply to designated financial entities.
Read the perspective
Test actor, object and workflow state together, with synthetic orders and independent read-back.
Read the perspective
Trace an exposed build credential through its identity, audience and permitted operations.
Read the perspectiveA PRACTICAL STARTING POINT
Bring systems, permissions, operating constraints and evidence needs together.

LET’S START A CONVERSATION
Your systems, operating constraints and security objectives. A clear starting point for the test.
Discuss your pentest