Web application penetration testing

Can one account reach another customer’s data?

Authenticated testing of SaaS products and web applications across your agreed roles.

Human-led testing.
Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we investigate

A scope with a purpose.

Identity and access

Sign-in, password recovery, session handling and privilege boundaries.

Tenant and data separation

Object access, exports and file handling between customer accounts.

Business logic

Approval steps, pricing and account changes that should not be bypassed.

Before testing

What we need from you

  • Application URLs and the workflows that matter.
  • A role matrix plus test accounts within and across tenants.
  • Connected APIs named explicitly, not assumed.
Use the scoping checklist
After testing

What you can act on

  • Prioritised application risk by role and workflow.
  • Request or browser evidence for each finding.
  • A practical remediation direction your engineers can follow.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Third-party services and source-code review.
  • Denial of service.
  • Every connected API. Include them deliberately.
  • Production access without written authorisation.
Instant quote

Get an instant quote in 2 minutes

Answer four questions. The indicative price updates as you go. Prices are ex GST.

Indicative until we confirm scope in writing, within one business day. We use your details only to reply. See our Privacy notice.

Questions before you book

Practical answers.

Is staging enough?

A representative staging environment reduces operational risk. We record any difference from production because that difference limits what the result establishes.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Most web applications are tested alongside something else. If the product is mainly an interface over a service, API penetration testing covers where the logic actually lives, and the account it runs in is cloud penetration testing. Before you buy, read what a penetration test report should contain and how to scope a penetration test.

Let’s scope it

Let’s define your web applications test.

Share the assets and your reason for testing. We will confirm the approach, fee and schedule.

Request a quote

Last reviewed: