Application Security

Web Application Security

Manual and automated review of authentication, access control, input handling and business logic.

WHAT WE REVIEW

Focused work, defined around your environment.

authentication, authorisation, input handling, sessions, business logic and sensitive-data exposure.

Typical deliverables

GOOD TO KNOW

Authorisation

Testing is performed only against systems and assets you are authorised to have assessed.

Production safety

Production testing is not assumed. Scope and safeguards are agreed explicitly.

Confidentiality

Do not submit passwords, private keys or customer personal data through ordinary forms.