Home / Services / Web application VAPT

Web application VAPT

Web penetration testing for UK product teams.

Manual-first testing of the web applications your UK customers log into — authorisation, session, injection, business logic — written up for Cyber Essentials Plus, ISO 27001 and enterprise due diligence.

A development workstation — the surface a web application pentest actually starts from.
A development workstation — the surface a web application pentest actually starts from.

Coverage

Beyond a scanner-shaped OWASP Top 10

Authentication & session

Login, reset, MFA bypass, session fixation, token reuse, OAuth / SSO gaps, and account-takeover chains against a second test identity.

MFA bypassOAuthJWT

Access control

IDOR / BOLA, function-level auth, privilege escalation, multi-tenant isolation, hidden admin.

IDORTenancyBFLA

Injection & XSS

SQL / NoSQL, command injection, SSTI, XXE, reflected / stored / DOM XSS, second-order bugs.

SQLiXSSSSTI

Business logic & request integrity

Workflow skip, races, price and voucher abuse, CSRF, upload, SSRF, smuggling where the stack allows it.

LogicCSRFSSRF

Most UK SaaS products do not fail because of a 2014 SQLi. They fail because user 2 can read user 1’s invoices by changing a UUID they were never meant to know. Typical window: 3–5 working days. Written CMA 1990 authorisation first. Re-test included.

Ready to scope a UK engagement?

A thirty-minute call. Assets, timeline, a quote in pounds sterling.

Request a quote