Penetration testing for web applications & APIs
Find exploitable weaknesses before they disrupt your business.
A customer portal, partner API or business-critical web application needs a clear view of its security risks. Within an agreed scope, we examine whether technical and business-logic weaknesses can be exploited. Reproducible findings and practical remediation guidance give your development team a clear path forward.

Your options
Services that move your project forward
Define the scope and rules
We agree on target systems, roles, test accounts and permitted methods. Named contacts, communication channels and stop conditions support a controlled engagement.
A controlled test with clear boundaries.
Examine authentication and sessions
We examine selected authentication and session flows, including relevant error cases. The actual application configuration is included.
Weaknesses in central access routes are assessed in a comprehensible manner.
Test roles and object access
We check permissions across user roles and data objects, with particular attention to boundaries between customers or tenants.
Identify access that violates your intended business rules.
Check inputs and interfaces
Selected input paths, API endpoints, and data processing are examined for relevant vulnerabilities. Automated tools are supplemented by manual testing.
Findings refer to the specific behavior of your application.
Examine business logic
We examine multi-step workflows, approvals and sensitive actions using realistic abuse scenarios. Technical controls and business rules are assessed together.
Risks beyond standardized scan results become visible.
Report and retest
We document confirmed findings, effects and remedial instructions. A separately arranged follow-up test checks the corrected areas.
Your team can implement and review measures in a comprehensible way.
Where to start
Penetration testing for web applications & APIs Use cases
Three example situations show how we can help.
Before the portal starts
A new portal processes customer data. A test examines agreed functions and roles before the introduction and prioritizes necessary corrections.
After major changes
New logins, multi-tenancy or sensitive API functions change the attack surface. A targeted test focuses on these changes and their interfaces.
For an external security requirement
A customer requires a traceable technical review. We tailor the scope, report format, and appropriate evidence to the specific requirement.
From requirements to results
A clear process with agreed milestones
Prepare the test
We agree on the scope, authorization to test, test accounts and communication channels.
Examine the application
Manual and supporting automated checks follow the agreed goals and roles.
Explain the findings
We explain confirmed findings with technical evidence and a clear account of their business relevance.
Verify the fixes
On request, we will check the agreed fixes and document the remaining status.
Your benefit
What you receive
- Coordinated test rules and documented scope of testing.
- Technical report with reproducible confirmed findings.
- Management summary and prioritized remediation notes.
- An optional retest report covering the agreed fixes.
Ways to work with us
Choose a starting point that fits your needs. We agree the scope and required effort in a tailored proposal.
Web application penetration test
For portals and specialist applications: coordinated functions and roles with technical report and results discussion.
Request a quote: Web application penetration testAPI penetration test
For internal or external APIs: access controls, data objects and relevant business processes to the agreed extent.
Request a quote: API penetration testRemediation retest
For completed corrections: focused follow-up test of the previously identified weak points.
Request a quote: Remediation retestQuestions before you get started
Is an automatic vulnerability scan enough?
A scan can detect known patterns, but captures business rules and complex authorization errors to a limited extent. A penetration test complements the tools with manual examination and evaluation of the specific application.
Do you test with or without user credentials?
Both are possible and are selected based on the test objectives. Provided test accounts help to specifically examine different roles and protected functions. The chosen approach is documented in the report.
Can testing take place in production?
This requires explicit agreement. A suitable test environment is often preferable. For production systems, testing windows, permitted methods, named contacts and stop conditions are defined carefully in advance.
Who is allowed to commission a penetration test?
The engagement must be authorized by a party entitled to permit testing of the systems concerned. Third-party rights and the relevant operators’ terms are considered before testing begins.
What methodology is used?
Testing follows the agreed risks and may draw on established guidance such as the OWASP Web Security Testing Guide. The actual scope and coverage are documented so that readers can understand what was examined.
What happens in the event of a particularly critical finding?
We agree on a communication channel for urgent results in advance. This allows responsible persons to decide on suitable measures in a timely manner before the complete final report is available.
Is the follow-up test automatically included?
The follow-up test is expressly described in the offer. The scope, number of corrections checked and time requirements are agreed upon so that the later evaluation remains plannable.
Does a completed test confirm that the application is fully secure?
No. A penetration test is limited in scope and time. It provides valuable findings about the tested version and complements secure development, regular maintenance and other security measures.
Discuss your next step
Which application would you like to have specifically tested?
Let us know the type of application, the desired date and the relevant user roles. We clarify the scope and requirements for a specific test offer.
Penetration testing for web applications & APIs
Your next step
Tell us what you need. We will route your enquiry to the right team and discuss the next steps with you.
Fields marked * are required. Phone, company and postal address are optional.