Object and function access
Whether changing an identifier crosses a role or tenant boundary.
REST and GraphQL testing focused on object-level access and token boundaries.
Human-led testing.
Manually verified findings.
Whether changing an identifier crosses a role or tenant boundary.
Authentication flows, token expiry and unsafe data exposure in responses.
Multi-step operations, GraphQL access patterns and webhooks.
Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.
Yes, but discovery takes time and makes coverage less predictable. We agree the discovered endpoint inventory and name the blind spots rather than implying complete coverage.
From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.
Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.
An API is rarely the whole scope. The interface in front of it is web application penetration testing, a native client is mobile application penetration testing, and the account underneath is cloud penetration testing. Bring an OpenAPI specification and two accounts per role, for the reasons set out in how to scope a penetration test.
Only your email is required. Scope and fee are agreed in writing.
Last reviewed: