Web application penetration testing
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Application security
Manual review of source code, supported by static analysis, for vulnerabilities that cannot be seen from outside.
Application security
Some vulnerabilities leave no trace in the behaviour of a running system until the day they are exploited: a missing check in a rarely used branch, a weak random generator, a secret in the history of the repository. They are visible in the code.
We read the code the way an attacker would if it leaked. Static analysis tools mark the candidates, specialists trace the data from entry point to sink and decide what is real. The review covers the code you wrote, the dependencies you imported and the pipeline that builds them, including code produced with AI assistants.
01Scope
02Approach
We start from what matters: the functions that handle money, identity and secrets. The architecture is read first, the code second.
Static analysis, dependency analysis and secret scanning produce candidates. Custom rules are written for the patterns specific to your code.
Each candidate is traced from the entry point to the sink. False positives are discarded, real issues are confirmed in a running instance where possible.
When a flaw is found, the whole code base is searched for its variants. One finding usually has relatives.
03
04
05Standards
Requirements an application is verified against.
OWASP Foundation
The most critical risks of web applications; a minimum, not a method.
OWASP Foundation
Class of weakness behind every finding.
The MITRE Corporation
Severity score and vector of every finding.
FIRST
06Questions
Access is granted to named specialists, the code is analysed in an isolated environment and is not copied outside it. Working copies are destroyed 30 days after the engagement is closed. The code is never submitted to public AI services.
An analyser reports patterns. It does not know which of them is reachable, and it does not see a missing authorisation check, because a missing line matches no pattern. The review answers both questions.
Yes. A review of a single component, of the changes since a release or of one pull request is a normal scope.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.