Skip to content

Penetration testing for web applications & APIs

Find exploitable weaknesses before they disrupt your business.

A customer portal, partner API or business-critical web application needs a clear view of its security risks. Within an agreed scope, we examine whether technical and business-logic weaknesses can be exploited. Reproducible findings and practical remediation guidance give your development team a clear path forward.

Symbolic image: Protection and controlled access.

Your options

Services that move your project forward

Define the scope and rules

We agree on target systems, roles, test accounts and permitted methods. Named contacts, communication channels and stop conditions support a controlled engagement.

Your benefit

A controlled test with clear boundaries.

Examine authentication and sessions

We examine selected authentication and session flows, including relevant error cases. The actual application configuration is included.

Your benefit

Weaknesses in central access routes are assessed in a comprehensible manner.

Test roles and object access

We check permissions across user roles and data objects, with particular attention to boundaries between customers or tenants.

Your benefit

Identify access that violates your intended business rules.

Check inputs and interfaces

Selected input paths, API endpoints, and data processing are examined for relevant vulnerabilities. Automated tools are supplemented by manual testing.

Your benefit

Findings refer to the specific behavior of your application.

Examine business logic

We examine multi-step workflows, approvals and sensitive actions using realistic abuse scenarios. Technical controls and business rules are assessed together.

Your benefit

Risks beyond standardized scan results become visible.

Report and retest

We document confirmed findings, effects and remedial instructions. A separately arranged follow-up test checks the corrected areas.

Your benefit

Your team can implement and review measures in a comprehensible way.

Where to start

Penetration testing for web applications & APIs Use cases

Three example situations show how we can help.

Before the portal starts

A new portal processes customer data. A test examines agreed functions and roles before the introduction and prioritizes necessary corrections.

After major changes

New logins, multi-tenancy or sensitive API functions change the attack surface. A targeted test focuses on these changes and their interfaces.

For an external security requirement

A customer requires a traceable technical review. We tailor the scope, report format, and appropriate evidence to the specific requirement.

From requirements to results

A clear process with agreed milestones

  1. Prepare the test

    We agree on the scope, authorization to test, test accounts and communication channels.

  2. Examine the application

    Manual and supporting automated checks follow the agreed goals and roles.

  3. Explain the findings

    We explain confirmed findings with technical evidence and a clear account of their business relevance.

  4. Verify the fixes

    On request, we will check the agreed fixes and document the remaining status.

Your benefit

What you receive

  • Coordinated test rules and documented scope of testing.
  • Technical report with reproducible confirmed findings.
  • Management summary and prioritized remediation notes.
  • An optional retest report covering the agreed fixes.

Ways to work with us

Choose a starting point that fits your needs. We agree the scope and required effort in a tailored proposal.

Questions before you get started

Is an automatic vulnerability scan enough?

A scan can detect known patterns, but captures business rules and complex authorization errors to a limited extent. A penetration test complements the tools with manual examination and evaluation of the specific application.

Do you test with or without user credentials?

Both are possible and are selected based on the test objectives. Provided test accounts help to specifically examine different roles and protected functions. The chosen approach is documented in the report.

Can testing take place in production?

This requires explicit agreement. A suitable test environment is often preferable. For production systems, testing windows, permitted methods, named contacts and stop conditions are defined carefully in advance.

Who is allowed to commission a penetration test?

The engagement must be authorized by a party entitled to permit testing of the systems concerned. Third-party rights and the relevant operators’ terms are considered before testing begins.

What methodology is used?

Testing follows the agreed risks and may draw on established guidance such as the OWASP Web Security Testing Guide. The actual scope and coverage are documented so that readers can understand what was examined.

What happens in the event of a particularly critical finding?

We agree on a communication channel for urgent results in advance. This allows responsible persons to decide on suitable measures in a timely manner before the complete final report is available.

Is the follow-up test automatically included?

The follow-up test is expressly described in the offer. The scope, number of corrections checked and time requirements are agreed upon so that the later evaluation remains plannable.

Does a completed test confirm that the application is fully secure?

No. A penetration test is limited in scope and time. It provides valuable findings about the tested version and complements secure development, regular maintenance and other security measures.

Discuss your next step

Which application would you like to have specifically tested?

Let us know the type of application, the desired date and the relevant user roles. We clarify the scope and requirements for a specific test offer.

Discuss your project

Penetration testing for web applications & APIs

Your next step

Tell us what you need. We will route your enquiry to the right team and discuss the next steps with you.

Fields marked * are required. Phone, company and postal address are optional.

Your enquiry

Your enquiry

Penetration testing for web applications & APIs

What would you like to discuss? *

How to reach you

Your message

Add a postal address (optional)

Only provide an address if it is useful for your enquiry. Please enter the complete address. We check the format; this does not verify actual deliverability.

We use your details to handle your enquiry and send an acknowledgement by email. This does not subscribe you to a newsletter. Please do not send passwords, bank details or highly confidential information.

Privacy information for enquiries

Quick contact