Application Security
Assess APIs for broken authorisation, data exposure, injection and abuse paths.
WHAT WE REVIEW
endpoint discovery, authentication, authorisation, object-level access, data exposure and abuse paths.
GOOD TO KNOW
Testing is performed only against systems and assets you are authorised to have assessed.
Production testing is not assumed. Scope and safeguards are agreed explicitly.
Do not submit passwords, private keys or customer personal data through ordinary forms.