Skip to content
steelabs

04 /Services

Security & Vulnerability Assessment

We assess web applications and APIs against the OWASP Top 10 and related security standards: authentication, access control, injection, misconfiguration and more. You receive a prioritised report with reproduction details and concrete remediation guidance, not a raw scanner dump.

Scope

What’s included

Assessment coverage

  • OWASP Top 10 web application testing

    Manual testing against the OWASP Top 10 categories, with every finding demonstrated rather than inferred from a scanner’s output.

  • API security testing (authentication, authorisation, input handling)

    Probed directly at the API, where controls the interface appears to enforce frequently turn out not to exist.

  • Authentication and session management review

    Login, session lifetime, logout, password reset and multi-factor paths — where a working feature and a secure one diverge.

  • Access control and privilege escalation testing

    Attempting one user’s actions as another, and a lower role’s session against higher-privilege operations. Consistently the most valuable part of an assessment.

  • Security misconfiguration and information disclosure review

    Headers, error handling, exposed endpoints and verbose responses — low-effort findings, which also makes them low-effort for someone else to find.

  • Dependency and known-vulnerability scanning

    Vulnerable packages identified and then triaged by whether the vulnerable path is actually reachable in your application.

Follow-up

  • Remediation guidance sessions with your developers

    A working session on how to fix what was found, so the report becomes changes rather than a ticket nobody knows how to start.

  • Retesting of fixed findings with updated report

    The fixes verified and the report reissued — that reissued version is the one you can hand to a customer or an auditor.

  • Security recommendations for your development process

    The practices that would have caught these findings earlier, scoped to what your team can realistically adopt.

Sound familiar?

  • An enterprise prospect or partner is asking for evidence of security testing.

  • You handle sensitive data and have never had an independent security review.

  • Compliance or procurement requires a documented vulnerability assessment.

  • Your team fixes security issues reactively, after incidents, instead of before them.

What you get out of it

Outcomes, not deliverables theatre

  • A clear picture of your real security posture, mapped to OWASP categories.

  • Vulnerabilities ranked by severity and business impact — you know what to fix first.

  • A professional report you can share with customers, partners and auditors.

  • Concrete remediation guidance your developers can implement directly.

Approach

How the engagement runs

  1. 01

    Scoping & rules of engagement

    We agree targets, test environment, accounts, boundaries and timing in writing before any testing begins.

  2. 02

    Assessment

    Systematic OWASP-based testing combining manual techniques with tooling — scanners find the obvious, humans find the exploitable.

  3. 03

    Reporting

    Findings are documented with severity, impact, reproduction steps and remediation guidance, plus an executive summary.

  4. 04

    Remediation & retest

    We walk your developers through the fixes, then retest and issue an updated report you can share externally.

Deliverables

What lands in your hands

  1. 01

    Vulnerability assessment report with severity-ranked findings

  2. 02

    Reproduction details and evidence for each finding

  3. 03

    Prioritised remediation plan with concrete guidance

  4. 04

    Executive summary suitable for non-technical stakeholders

  5. 05

    Retest report confirming resolved findings

Technologies, ideal clients and industries

Typical toolset

OWASP ZAPBurp SuitePostmannpm audit / dependency scanning

A good fit if you are

  • SaaS companies facing enterprise security questionnaires
  • Products handling personal, financial or health data
  • Teams preparing for compliance audits or certification
  • Any business that has never had an independent security review

08 /FAQ

Security assessment questions

Is this a penetration test?

It is an application security assessment based on the OWASP methodology, focused on your web application and APIs. If you need a formal penetration test with a specific certification attached, we will tell you plainly and point you toward it rather than relabelling what we do. The practical difference is scope and framing: this examines your application in depth — authentication, authorisation, input handling, configuration, dependencies — and produces demonstrated findings with remediation guidance. It is not a network-wide or physical-security exercise, and it does not carry a certification body’s stamp. For most teams facing a customer security questionnaire, this is the work that answers it.

Will testing affect our production systems?

We prefer to test in a staging environment that mirrors production, and we agree the rules of engagement in writing before anything starts — scope, timing, what is explicitly out of bounds, and who to contact if something looks wrong. Where production testing is genuinely necessary, we schedule it with you and stay within limits you set. Some checks are intrusive by nature, and those are named in advance rather than discovered afterwards. You will always know what is being tested and when. If a finding turns out to be more serious than the report cadence assumes, we tell you immediately rather than saving it for the write-up.

What do we get at the end?

A written report with findings ranked by severity, each with reproduction steps, evidence and specific remediation guidance — plus a session with your developers to work through the fixes. The report is written to be read by two audiences: your engineers, who need enough detail to reproduce and fix, and a reviewer or customer who needs to see that the work was done and what came of it. Findings are demonstrated rather than inferred from a scanner, and severity reasoning is shown so you can disagree with it. Retesting the fixes and reissuing the report is included, and that reissued version is the one worth sharing externally.

Contact

Know your weaknesses before someone else does

Tell us about your application and what's driving the assessment — an enterprise deal, compliance, or plain diligence. Scoping is free and confidential.