Penetration testing for web applications & APIs
Find exploitable weaknesses before they disrupt your business.
A customer portal, partner API or business-critical web application needs a clear view of its security risks. Within an agreed scope, we examine whether technical and business-logic weaknesses can be exploited. Reproducible findings and practical remediation guidance give your development team a clear path forward.

Your options
Services that move your project forward
Define the scope and rules
We agree on target systems, roles, test accounts and permitted methods. Named contacts, communication channels and stop conditions support a controlled engagement.
A controlled test with clear boundaries.
Examine authentication and sessions
We examine selected authentication and session flows, including relevant error cases. The actual application configuration is included.
Weaknesses in central access routes are assessed in a comprehensible manner.
Test roles and object access
We check permissions across user roles and data objects, with particular attention to boundaries between customers or tenants.
Identify access that violates your intended business rules.
Check inputs and interfaces
Selected input paths, API endpoints, and data processing are examined for relevant vulnerabilities. Automated tools are supplemented by manual testing.
Findings refer to the specific behavior of your application.
Examine business logic
We examine multi-step workflows, approvals and sensitive actions using realistic abuse scenarios. Technical controls and business rules are assessed together.
Risks beyond standardized scan results become visible.
Report and retest
We document confirmed findings, effects and remedial instructions. A separately arranged follow-up test checks the corrected areas.
Your team can implement and review measures in a comprehensible way.
Where to start
Penetration testing for web applications & APIs Use cases
Three example situations show how we can help.
Before the portal starts
A new portal processes customer data. A test examines agreed functions and roles before the introduction and prioritizes necessary corrections.
After major changes
New logins, multi-tenancy or sensitive API functions change the attack surface. A targeted test focuses on these changes and their interfaces.
For an external security requirement
A customer requires a traceable technical review. We tailor the scope, report format, and appropriate evidence to the specific requirement.
From requirements to results
A clear process with agreed milestones
Prepare the test
We agree on the scope, authorization to test, test accounts and communication channels.
Examine the application
Manual and supporting automated checks follow the agreed goals and roles.
Explain the findings
We explain confirmed findings with technical evidence and a clear account of their business relevance.
Verify the fixes
On request, we will check the agreed fixes and document the remaining status.
Your benefit
What you receive
- Coordinated test rules and documented scope of testing.
- Technical report with reproducible confirmed findings.
- Management summary and prioritized remediation notes.
- An optional retest report covering the agreed fixes.
Ways to work with us
Choose a starting point that fits your needs. We agree the scope and required effort in a tailored proposal.
Web application penetration test
For portals and specialist applications: coordinated functions and roles with technical report and results discussion.
API penetration test
For internal or external APIs: access controls, data objects and relevant business processes to the agreed extent.
Remediation retest
For completed corrections: focused follow-up test of the previously identified weak points.
Questions before you get started
Is an automatic vulnerability scan enough?
A scan can detect known patterns, but captures business rules and complex authorization errors to a limited extent. A penetration test complements the tools with manual examination and evaluation of the specific application.
Do you test with or without user credentials?
Both are possible and are selected based on the test objectives. Provided test accounts help to specifically examine different roles and protected functions. The chosen approach is documented in the report.
Can testing take place in production?
This requires explicit agreement. A suitable test environment is often preferable. For production systems, testing windows, permitted methods, named contacts and stop conditions are defined carefully in advance.
Who is allowed to commission a penetration test?
The engagement must be authorized by a party entitled to permit testing of the systems concerned. Third-party rights and the relevant operators’ terms are considered before testing begins.
What methodology is used?
Testing follows the agreed risks and may draw on established guidance such as the OWASP Web Security Testing Guide. The actual scope and coverage are documented so that readers can understand what was examined.
What happens in the event of a particularly critical finding?
We agree on a communication channel for urgent results in advance. This allows responsible persons to decide on suitable measures in a timely manner before the complete final report is available.
Is the follow-up test automatically included?
The follow-up test is expressly described in the offer. The scope, number of corrections checked and time requirements are agreed upon so that the later evaluation remains plannable.
Does a completed test confirm that the application is fully secure?
No. A penetration test is limited in scope and time. It provides valuable findings about the tested version and complements secure development, regular maintenance and other security measures.
Discuss your next step
Which application would you like to have specifically tested?
Let us know the type of application, the desired date and the relevant user roles. We clarify the scope and requirements for a specific test offer.
Products for your project
Find manufacturers and product families that fit your needs. We help you plan selection, integration and operations.
manufacturers found
No matches. Try another search term or reset the filters.
Armis
Asset visibility and cyber exposure management
Armis Centrix — Asset Management and Security · Armis Centrix — OT/IoT Security · Armis Centrix — Medical Device Security
Products and use cases: Armis →BeyondTrust
Control privileged access
Password Safe · Privileged Remote Access · Endpoint Privilege Management
Products and use cases: BeyondTrust →BlueFlag Security
Identify risks in development identities
Developer Risk and Governance Platform
Products and use cases: BlueFlag Security →Check Point
Secure networks, cloud and endpoints
Next Generation Firewalls · Spark Firewalls · Cloud Firewall · Email Security · Endpoint Security
Products and use cases: Check Point →Corelight
Network detection and response
Open NDR Platform · Corelight Sensors · Corelight Investigator
Products and use cases: Corelight →Cybereason
Endpoint protection and attack detection
Cybereason EDR · Cybereason XDR · Cybereason NGAV
Products and use cases: Cybereason →CYREBRO
Managed detection and response
Managed Detection and Response · CYREBRO SOC Platform · Incident Response
Products and use cases: CYREBRO →Enginsight
IT visibility and security assessment
Enginsight Platform · Enginsight SIEM · Vulnerability Management & Pentesting
Products and use cases: Enginsight →Exabeam
SIEM and behavior-based detection
New-Scale SIEM · New-Scale Fusion · New-Scale Analytics
Products and use cases: Exabeam →Fortinet
Network security and secure access
FortiGate · FortiSASE · FortiEDR / FortiXDR · FortiManager / FortiAnalyzer
Products and use cases: Fortinet →Horizon3.ai
Validate attack paths and remediation
NodeZero Autonomous Pentesting · NodeZero AD Password Audit
Products and use cases: Horizon3.ai →Kaspersky
Endpoint protection and XDR
Kaspersky Next EDR Foundations · Kaspersky Next XDR Expert · Kaspersky Hybrid Cloud Security
Products and use cases: Kaspersky →Microsoft
Cloud, identities and security
Microsoft 365 / Azure · Microsoft Entra / Intune · Microsoft Defender / Sentinel · Microsoft Purview
Products and use cases: Microsoft →N-able
IT management and recovery
N-central Endpoint Management · N-sight Endpoint Management · Cove Data Protection · Passportal
Products and use cases: N-able →NETSCOUT
Network analytics and DDoS protection
nGeniusONE · Omnis Cyber Intelligence / Streamer · Arbor Edge Defense
Products and use cases: NETSCOUT →Rapid7
Vulnerabilities and attack surfaces
Exposure Command / InsightVM · InsightAppSec · InsightCloudSec · Metasploit
Products and use cases: Rapid7 →Sekoia.io
SIEM and threat intelligence
Sekoia Defend · Sekoia Intelligence
Products and use cases: Sekoia.io →SentinelOne
Endpoint protection and security operations
Singularity Endpoint · Singularity Identity · Singularity Cloud Security · Singularity AI SIEM
Products and use cases: SentinelOne →Sophos
Endpoint, firewall and managed detection
Sophos Endpoint · Sophos Firewall · Sophos MDR · Sophos Central
Products and use cases: Sophos →Torq
Security operations automation
Torq Hyperautomation · Torq HyperAgents · Torq Case Management
Products and use cases: Torq →Trellix
Endpoint, data and network security
Trellix Endpoint Security · Trellix Data Security · Trellix Network Security · Trellix Helix
Products and use cases: Trellix →Tripwire
Integrity and security configuration
Tripwire Enterprise · Tripwire IP360 · Tripwire LogCenter
Products and use cases: Tripwire →Varonis
Data security and access permissions
Varonis Discovery / DSPM · Varonis Data Access Governance · Varonis Data Detection and Response
Products and use cases: Varonis →WatchGuard
Network, endpoint and identity protection
WatchGuard Firebox · WatchGuard AuthPoint · WatchGuard Endpoint Security · WatchGuard ThreatSync
Products and use cases: WatchGuard →