Penetration testing for web, API and LLM applications.

Testing of web applications, APIs and LLM-based applications for exploitable weaknesses. Each finding comes with evidence, a severity rating and a practical fix, followed by a retest once remediated.

WHAT'S COVERED

  • Web applications: authentication, session handling, access control, input handling and business logic
  • APIs: REST and GraphQL, object- and function-level authorisation, rate limiting and data exposure
  • LLM-based applications: prompt injection, insecure output handling, sensitive information disclosure and excessive agency
  • Retesting of remediated findings

WHAT YOU RECEIVE

  • A report with an executive summary and full technical detail
  • Every finding with evidence, a severity rating and a practical fix
  • A retest once fixes are in place, with each finding’s updated status

BEST PRACTICE

  • OWASP Top 10:2025OWASP Foundation
  • OWASP API Security Top 10 2023OWASP Foundation
  • OWASP Top 10 for LLM Applications 2025OWASP GenAI Security Project
  • OWASP Web Security Testing Guide (WSTG) v4.2OWASP Foundation
NEXT STEP

Discuss a penetration test.

Describe what you need and we will reply within one business day.

Get in touch All services

OTHER SERVICES

02Security automation03Data protection and privacy04Security governance and risk