04 /Services
Security & Vulnerability Assessment
We assess web applications and APIs against the OWASP Top 10 and related security standards: authentication, access control, injection, misconfiguration and more. You receive a prioritised report with reproduction details and concrete remediation guidance, not a raw scanner dump.
Scope
What’s included
Assessment coverage
OWASP Top 10 web application testing
Manual testing against the OWASP Top 10 categories, with every finding demonstrated rather than inferred from a scanner’s output.
API security testing (authentication, authorisation, input handling)
Probed directly at the API, where controls the interface appears to enforce frequently turn out not to exist.
Authentication and session management review
Login, session lifetime, logout, password reset and multi-factor paths — where a working feature and a secure one diverge.
Access control and privilege escalation testing
Attempting one user’s actions as another, and a lower role’s session against higher-privilege operations. Consistently the most valuable part of an assessment.
Security misconfiguration and information disclosure review
Headers, error handling, exposed endpoints and verbose responses — low-effort findings, which also makes them low-effort for someone else to find.
Dependency and known-vulnerability scanning
Vulnerable packages identified and then triaged by whether the vulnerable path is actually reachable in your application.
Follow-up
Remediation guidance sessions with your developers
A working session on how to fix what was found, so the report becomes changes rather than a ticket nobody knows how to start.
Retesting of fixed findings with updated report
The fixes verified and the report reissued — that reissued version is the one you can hand to a customer or an auditor.
Security recommendations for your development process
The practices that would have caught these findings earlier, scoped to what your team can realistically adopt.
Sound familiar?
An enterprise prospect or partner is asking for evidence of security testing.
You handle sensitive data and have never had an independent security review.
Compliance or procurement requires a documented vulnerability assessment.
Your team fixes security issues reactively, after incidents, instead of before them.
What you get out of it
Outcomes, not deliverables theatre
A clear picture of your real security posture, mapped to OWASP categories.
Vulnerabilities ranked by severity and business impact — you know what to fix first.
A professional report you can share with customers, partners and auditors.
Concrete remediation guidance your developers can implement directly.
Approach
How the engagement runs
- 01
Scoping & rules of engagement
We agree targets, test environment, accounts, boundaries and timing in writing before any testing begins.
- 02
Assessment
Systematic OWASP-based testing combining manual techniques with tooling — scanners find the obvious, humans find the exploitable.
- 03
Reporting
Findings are documented with severity, impact, reproduction steps and remediation guidance, plus an executive summary.
- 04
Remediation & retest
We walk your developers through the fixes, then retest and issue an updated report you can share externally.
Deliverables
What lands in your hands
- 01
Vulnerability assessment report with severity-ranked findings
- 02
Reproduction details and evidence for each finding
- 03
Prioritised remediation plan with concrete guidance
- 04
Executive summary suitable for non-technical stakeholders
- 05
Retest report confirming resolved findings
Technologies, ideal clients and industries
- SaaS companies facing enterprise security questionnaires
- Products handling personal, financial or health data
- Teams preparing for compliance audits or certification
- Any business that has never had an independent security review
08 /FAQ
Security assessment questions
Is this a penetration test?
It is an application security assessment based on the OWASP methodology, focused on your web application and APIs. If you need a formal penetration test with a specific certification attached, we will tell you plainly and point you toward it rather than relabelling what we do. The practical difference is scope and framing: this examines your application in depth — authentication, authorisation, input handling, configuration, dependencies — and produces demonstrated findings with remediation guidance. It is not a network-wide or physical-security exercise, and it does not carry a certification body’s stamp. For most teams facing a customer security questionnaire, this is the work that answers it.
Will testing affect our production systems?
We prefer to test in a staging environment that mirrors production, and we agree the rules of engagement in writing before anything starts — scope, timing, what is explicitly out of bounds, and who to contact if something looks wrong. Where production testing is genuinely necessary, we schedule it with you and stay within limits you set. Some checks are intrusive by nature, and those are named in advance rather than discovered afterwards. You will always know what is being tested and when. If a finding turns out to be more serious than the report cadence assumes, we tell you immediately rather than saving it for the write-up.
What do we get at the end?
A written report with findings ranked by severity, each with reproduction steps, evidence and specific remediation guidance — plus a session with your developers to work through the fixes. The report is written to be read by two audiences: your engineers, who need enough detail to reproduce and fix, and a reviewer or customer who needs to see that the work was done and what came of it. Findings are demonstrated rather than inferred from a scanner, and severity reasoning is shown so you can disagree with it. Retesting the fixes and reissuing the report is included, and that reissued version is the one worth sharing externally.
Related reading
- Application security
OWASP assessment vs penetration test: which one your requirement names
Suppliers use the two terms interchangeably. Contracts, insurers and regulators do not. How to read the clause you have been given before you buy the wrong thing.
- Application security
Broken object level authorisation: the API risk no scanner will find for you
The top entry on the OWASP API Security Top 10 returns a perfectly normal 200 to the wrong person. Why tooling cannot see it, and how the testing actually runs.
- Application security
Triaging dependency vulnerabilities: what to do with 400 open alerts
A scanner dashboard nobody opens is worse than no scanner. How to sort advisories by whether they can actually be triggered, and how to record the ones you defer.
Contact
Know your weaknesses before someone else does
Tell us about your application and what's driving the assessment — an enterprise deal, compliance, or plain diligence. Scoping is free and confidential.