Authentication & session
Login, reset, MFA bypass, session fixation, token reuse, OAuth / SSO gaps, and account-takeover chains against a second test identity.
Home / Services / Web application VAPT
Web application VAPT
Manual-first testing of the web applications your UK customers log into — authorisation, session, injection, business logic — written up for Cyber Essentials Plus, ISO 27001 and enterprise due diligence.
Coverage
Login, reset, MFA bypass, session fixation, token reuse, OAuth / SSO gaps, and account-takeover chains against a second test identity.
IDOR / BOLA, function-level auth, privilege escalation, multi-tenant isolation, hidden admin.
SQL / NoSQL, command injection, SSTI, XXE, reflected / stored / DOM XSS, second-order bugs.
Workflow skip, races, price and voucher abuse, CSRF, upload, SSRF, smuggling where the stack allows it.
Most UK SaaS products do not fail because of a 2014 SQLi. They fail because user 2 can read user 1’s invoices by changing a UUID they were never meant to know. Typical window: 3–5 working days. Written CMA 1990 authorisation first. Re-test included.
A thirty-minute call. Assets, timeline, a quote in pounds sterling.
Request a quote