Scope and authorisation
Assets, test accounts, conditions, working windows and contacts agreed before testing begins.
We test your web applications and APIs within an authorised scope. You see which vulnerabilities we find, what they can affect and how to address them.
You want to review access, data and sensitive functions before opening them to more users.
Authentication and permissions are in place, and you want to test how they behave.
You need to understand a vulnerability’s impact and check whether its fix resolved the issue.
Assets, test accounts, conditions, working windows and contacts agreed before testing begins.
Assessment of agreed surfaces and functions, including authentication, permissions and information exposure.
Each identified vulnerability is described with impact context and evidence your team can work with.
Remediation recommendations and a further check of findings included in the scope.
Define what can be tested, in which environment and under which conditions.
Deliverable: An authorised test plan and named owners.
Run agreed tests and communicate relevant findings through the defined channel.
Deliverable: Technical evidence and assessment progress.
Explain the report, prioritise fixes and review the ones agreed in the engagement.
Deliverable: Final report and the results of contracted verification.
In a portal, a test account tries to access a resource belonging to another role. If the control fails, the report explains the affected resource, context and proposed fix. This is an illustrative example, not a vulnerability attributed to a published project.
A step-by-step example to understand the problem and the work we can carry out.
What we assess in an application, how we prioritize findings and why we verify fixes.
Your application works. But do you know who can enter and what information they can see? First, we agree on what to assess and obtain authorisation. Then we check access, permissions and potential weaknesses in the applications and their connections. These penetration tests look for specific problems within the defined scope. Each finding comes with evidence, impact and a priority. We agree on what to fix, make the included changes and check them again. Your team receives a clear report and next steps. Tell us which system you want to assess, and let’s define an evaluation together.
We agree the project deliverables and quote any additional services you need separately.
An owner who can authorise testing, a list of assets and the application’s context. We agree access, test accounts, environment and conditions before running tests.
We define this according to the system and permitted conditions. The plan specifies environments, testing windows, allowed actions and incident coordination with your team.
The assessment delivers a report and recommendations. We can include remediation and another verification round in the proposal, with defined deliverables.
The report documents the results of the assessed scope and conditions. Security needs further review when features, access or infrastructure change.
We review applications, access and infrastructure to find weaknesses that put your operations at risk. You receive clear findings, priorities and a plan to address them.
We build online stores, portals and web applications that help people buy, request a quote or complete a task. We design the journey and connect payments, data and the tools behind your operation.
An order, enquiry or stock change should not require updating several tools by hand. We connect your applications so data reaches the right place and you can see what happened.
Share the application type, its users and the assessment goal. We will use that to define assets, conditions and deliverables.