Pay us to hack you.
Offensive Security & Web Application Penetration Testing
Your application works. We find out who else it works for.
We test web applications and the APIs behind them by hand, show you what an attacker could actually do, and tell your engineers exactly what to change.
- Tested by hand, not by a scanner
- You deal with the people doing the testing
- Retest of the findings included for fifteen days
Why manual
A scanner tells you what looks broken. We tell you what someone can actually do.
Automated tools find known problems. They cannot tell you your application is doing exactly what it was built to do, for the wrong person.
-
Another user's data
An account changes an identifier and reads a record belonging to someone else.
-
A workflow driven out of order
A mandatory step is skipped or repeated, and the application accepts the result.
-
An API that answers too much
The front end hides the button. The endpoint behind it still takes the call.
-
A role that reaches too far
A low-privilege account reaches an admin function, because the check lives in the interface.
-
Two harmless features, chained
Neither is a vulnerability alone. Used together, they are.
Want the longer version?
What we do
Offensive security, and nothing else.
Four angles on one question: what somebody can actually do with your application. An engagement is scoped across them rather than bought one at a time. Tell us what you made and who is meant to do what in it. Working out what is worth testing is our job, not yours.
-
Web Application Penetration Testing
We try to break into your application the way an attacker would.
-
API Penetration Testing
We test the API behind your app directly, including the requests your own app never makes.
-
Authentication & Authorisation Testing
We check that every account can only reach what it is meant to reach.
-
Business Logic Testing
We test your own rules on prices, limits, approvals and who owns what.
Where we stop
The other half is Skull Solutions.
We attack the application. How it should have been designed, and the engineering that closes what we find, is our parent company's work rather than ours. Same people to ask, different side of the line.
-
Application security consulting
Security architecture review, threat modelling, secure code review and attack surface review: how the application was designed, and what it was meant to defend against.
-
Secure software engineering
Closing findings in your codebase, and building the parts where getting the security wrong is the whole risk. Not general development, and never a product build with a security label on it.
Ask us either way. If what you need sits with Skull Solutions we will say so and hand you over, rather than stretch a testing engagement to cover it.
Who it is for
You own the software. Nobody owns the security.
-
Startups
You are shipping fast and nobody on the team owns security.
-
Small businesses
No security department, and a business that runs on one application.
-
Developers and agencies
An independent test before you hand something to a client.
-
Teams building with AI
AI writes the code. It does not review its own access control.
Not sure it is you?
How it works
Scope. Test. Report. Retest.
Nothing is touched before the scope is agreed in writing. Nothing is closed before the fix has been retested.
-
Scope
We agree in writing what we are allowed to test.
-
Test
We attack the application by hand, the way someone else would.
-
Report
You get what we found, how bad it is, and how to fix it.
-
Retest
Your team fixes it. We check that it is really fixed.
What a finding contains
-
What we found
The vulnerability in plain terms, and where it lives.
-
How we exploited it
The path actually taken, not the name of a category.
-
How to reproduce it
The requests and account state needed to see it happen.
-
Why it matters
What it would let someone do to your data, your users or your revenue.
-
How to fix it
The check that is missing, and where it belongs.
-
Whether the fix worked
A retest of the findings, included for fifteen days.
Want to know what arrives at the end?
Need your application tested?
Send a paragraph about what you built. That is enough to start.