Web Application Security Audit
A web application security audit that starts where attackers do.
A web application security audit tests your live app from the outside: what an unauthenticated stranger can read, write or trigger through your pages, APIs and database. We run exactly that test, then hand you the fix for everything we find.
From $750, fixed quote, report in about a week. See full pricing
The browser is not the attack surface. The API behind it is.
Your interface only shows each user their own data, so everything looks private. But the requests behind the interface tell the real story: the API that accepts any user ID, the storage bucket that lists its contents, the backend endpoint that skips the auth check. None of this is visible from the front end, which is why apps that look secure keep failing the same external test.
What you get.
Unauthenticated exposure test
We query your app with no login at all and document every table, file and endpoint that answers.
Cross-account testing
Two ordinary accounts, each trying to reach the other's data through every route we can find. The five-minute version of this test catches more than most scanners.
API and endpoint review
Every callable endpoint checked for missing auth, missing ownership checks and parameters that trust the client.
Keys and configuration
Which credentials ship in your pages, what they can do, and the platform settings that quietly widen them.
Prioritised report and re-review
Severity-rated findings with concrete fixes, and a free re-test once you have closed them.
The kind of thing we find
A health app exposed patient access codes and payment codes to anyone holding its public API key. Private in intent, public in fact, and completely invisible from the interface. It took one unauthenticated request to prove, which is one more than anyone had tried.
How it works.
- 01
Scope
Your app's URL and a short walkthrough. Much of the audit needs nothing more.
- 02
Test
We probe the live app from outside, by hand, the way an attacker actually works.
- 03
Report
Every finding written up with severity and fix, in about a week.
- 04
Re-review
We re-run the same probes after your fixes and confirm the doors are closed.
Common questions.
- What does a web application security audit include?
- External testing of your live app: unauthenticated access, cross-account access, API and endpoint auth, exposed keys and storage, plus a code-level review of what we find. Every finding is severity-rated with a fix.
- Is this the same as a website security audit?
- The terms overlap. If your site is mostly content, the audit focuses on configuration and exposure. If it is an application with accounts and data, the audit focuses on access control, which is where the serious findings live.
- Will the testing affect my live app?
- No. The audit reads and probes, it does not stress or damage. Anything that writes data is done against test accounts we create, and we tell you before we touch anything state-changing.
- How much does it cost?
- From $750 as a fixed quote, with the re-test of your fixes included.
Related services.
Let's build something real.
Tell us about your app or idea. You'll get a clear plan and a fixed quote back within 24 hours.
