Web Application Pentest
We test your web application for real risks before attackers find them. Our approach is based on the OWASP Testing Guide and goes beyond automated scanners.
What do we test?
- Authentication & sessions — password policy, MFA bypass, session management, token validation
- Authorization — broken access control, IDOR, privilege escalation, horizontal and vertical access flaws
- Input validation — SQL injection, XSS, command injection, file upload abuse
- Business logic — skipping process steps, price manipulation, race conditions
- API integrations — insecure API calls, exposed endpoints
- Configuration — security headers, TLS configuration, error handling
Approach: grey box
For web applications, we use a grey box approach by default: we have a user account but no source code. This simulates an attacker who gained access via phishing or credential stuffing. On request, we also carry out black box or white box pentests. More on this on the pentest methodology page.
Who is this for
- Organisations with a customer portal or user environment
- SaaS companies building software for business clients
- Organisations that must comply with NIS2, ISO 27001 or PCI DSS
- Development teams who want their application tested before or after a release
FAQ
Can this be done on a staging environment?
Yes, that’s often the best route. We also test on production if the client prefers — in that case we schedule it outside peak hours.
Do you include APIs?
Yes, APIs that are part of the web application are included. For an extensive API-only test, see API pentest.
How long does a web application pentest take?
Usually 3 to 5 business days, depending on the complexity of the application and the number of use cases.
Schedule a web application pentest · API pentest · Pricing
Compliance & Sector-Specific Pentests
Does your organisation operate under specific regulations? We carry out pentests tailored to your industry’s requirements.
- DigiD Pentest & IT Security Assessment — mandatory for organisations with a DigiD connection
- ISO 27001 Pentest — support for certification
- NIS2 Pentest — technical assessment for NIS2-obligated organisations
- PCI DSS Pentest — mandatory test for payment environments
- Government Pentest — BIO-aligned for the public sector
- Healthcare Pentest — NEN 7510 and GDPR-focused
- SaaS Pentest — for software and platform companies
