Authentication and sessions
Login, password reset, session handling, and the transitions between authenticated and unauthenticated access.
Utilities Studio / Cybersecurity
Find out whether one customer can reach another customer's data.
Test authentication, access controls, and business logic in your web application. Get reproducible findings and remediation guidance for your engineering team.
An enterprise customer wants a report, a release is approaching, or your permission model has changed. As a founder or engineering lead, you need coverage of the workflows that matter to your product. We test the agreed user roles and customer boundaries, with reproduction steps your developers can follow.
The assessment
Web application penetration testing investigates how an attacker could abuse an application and its server-side behavior. We test the roles, workflows, and interfaces in scope, including requests a normal user would never make through the interface. Findings explain the access required, the affected data or function, and how to reproduce the issue.
Login, password reset, session handling, and the transitions between authenticated and unauthenticated access.
Attempts to reach another user's records, another customer's data, or functions reserved for a different role.
Misuse of the agreed account, approval, purchase, or administrative workflows.
Injection risks, file handling, and server-side validation across the application interfaces in scope.
The WSTG provides a reference for web application security testing. Bring any required coverage or evidence mapping to the scoping call so it can be specified in the test plan.
OWASP Web Security Testing Guide (WSTG)Working with your team
Confirm the assets, permissions, and production limits. Name the contacts and record the dates, reporting format, support arrangements, and retest terms.
Investigate the agreed attack paths and validate findings. Keep your team updated and escalate critical issues immediately through the agreed channel.
Walk your engineers through the report and remediation priorities. Carry out the agreed retesting and document which fixes worked and what remains unresolved.
Pricing depends on application complexity, the number of user roles, sensitive workflows, and the depth of testing. Several domains can belong to one application; one domain can contain several distinct applications. We scope the work around behavior and access.
We confirm the testing window after reviewing the application and access requirements. Allow time for account setup, assessment, report review, and any retesting included in the proposal.
Pentest delivery
We share validated findings during the test through the agreed secure channel. Critical issues go to your nominated contact immediately. Progress updates cover completed work, blockers, and what comes next.
Your engineers get affected assets, reproduction steps, evidence, and remediation guidance. We explain severity using the demonstrated impact. An executive summary sets out the business risk and the limits of the assessment.
A technical findings review lets your engineers discuss the evidence and recommended fixes with us. We name the technical contact and agree the support period and response arrangements before testing.
Retesting checks fixes to the original findings and records the result. Before booking, we specify the findings covered, retest rounds, time window, and any charges. New features or changed environments need a scope review.
We agree the findings format and handover method with your team. If you use Jira, Linear, or GitHub, we scope the export or ticket handover, required access, and treatment of sensitive evidence before testing.
Your proposal sets the start date, testing window, and report delivery date after we review scope and access. Bring your audit or release deadline so remediation and retesting can be planned around it.
Delivery references: NIST SP 800-115 and CREST's penetration testing programme guide.
The practitioner behind the work
Sheeraz Ali is our Head of Cybersecurity. His work spans application, cloud, network, and AI assessments. His personal track record includes leading pentests at Cobalt and building the internal pentest programme at SolarWinds.
Read Sheeraz's security backgroundSheeraz's personal track record
His website lists OSCP, CRTP, CRTE, CREST CRT and CPSA, CBBH, and CKA.
At SolarWinds, he delivered 120+ internal pentests. As CTO at Pwned Labs, he built a platform serving 40,000+ practitioners. He co-developed Mobexler, selected for Black Hat Arsenal, and presented research at Nullcon and c0c0n.
Explore his career timelineFAQ
Yes, when authenticated testing is in scope. Provide accounts for the relevant roles so we can compare what each account should be able to do with what the application actually permits.
A scan can identify some classes of weakness. Testing account boundaries and business logic also requires understanding the intended behavior and attempting to bypass it. We agree the testing approach around the application and the risks that matter.
Yes. Identify the tenant model and provide test accounts for separate organizations and roles. The scope can examine cross-tenant access, shared resources, and administrative functions.
We identify the API endpoints used by the application during scoping. Broader API coverage, partner integrations, or endpoints outside the application may require a separate API assessment.
Bring the previous report and a list of changes to your code, permissions, or infrastructure. We can use those to scope the next assessment. Check which earlier findings were fixed and which fixes were verified; the date on the old report does not answer those questions.
Assess API authentication, object-level authorization, role boundaries, and sensitive data exposure. Get evidence your developers can reproduce.
Assess prompt injection, RAG data exposure, and agent tool abuse. Test the permissions and trust boundaries around your AI application.
Manual penetration testing for your applications, cloud, and networks. Get validated findings with reproduction steps, business impact, and guidance for your engineers.
Tell us what your team needs to resolve, which systems are involved, and any deadline. We will work through the scope and reporting needs with you.