Service

Pentesting
web applications and APIs

We find the vulnerabilities before someone else does. Manual analysis plus automation, exploitation, CVSS report and help with fixes.

Discuss your project Cases
OWASP Top 10 REST API GraphQL WebSocket SAST DAST Business Logic NDA Worldwide
14+
years in security
200+
projects
47
countries
100%
NDA

What we check

Full coverage of attack vectors for web applications and APIs

OWASP

Injections and XSS

SQL, NoSQL, LDAP, OS Command injection. Stored, Reflected and DOM-based XSS. Template injection.

Auth

Authorization and authentication

IDOR, broken access control, JWT vulnerabilities, OAuth misconfig, privilege escalation, session management.

API

REST and GraphQL APIs

Mass assignment, excessive data exposure, rate limiting bypass, introspection abuse, batch attacks.

Logic

Business logic

Race conditions, price manipulation, workflow bypass, coupon/promo abuse, multi-step attacks.

Infra

Server side

SSRF, XXE, path traversal, file upload bypass, deserialization, open redirect.

Config

Configuration and headers

Security headers, CORS misconfiguration, CSRF, clickjacking, information leaks in responses.

How we work

No red tape, clear stages and deadlines

01

Brief and NDA

We fix the scope: domains, endpoints, test accounts. NDA signed before any work starts. We estimate the volume and name the exact price.

02

Recon and mapping

Application map, endpoints, technologies, attack surface. Passive and active information gathering.

03

Testing

Automated scanners plus deep manual analysis. Exploitation of what we find, PoC for every critical issue.

04

Report

A document describing each vulnerability, its CVSS score, proof of exploitation and concrete remediation steps. Executive summary plus technical details.

05

Re-check

After you close the issues — we re-test for free to make sure everything is fixed properly.

Pricing

Exact price after a brief. Below are reference points.

from
$500

Base web application audit. The final price depends on the number of endpoints, business logic complexity and application type.

  • Full manual analysis
  • OWASP Top 10 coverage
  • Vulnerability exploitation (PoC)
  • CVSS score for every finding
  • Detailed report (EN or RU)
  • Free re-check after fixes
  • NDA by default

FAQ

Short and to the point

How much does a web app pentest cost?
From $500. The exact price depends on scope: number of endpoints, business logic complexity and application type. We quote after a short brief.
How long does an audit take?
A standard web application pentest takes 3–7 business days. Complex projects with unusual business logic — up to 14 days. Deadlines are fixed before we start.
Do you test GraphQL and WebSocket?
Yes. We work with REST, GraphQL, WebSocket and gRPC. The specifics of each protocol are taken into account — introspection abuse, batch attacks, non-standard vectors.
What if a vulnerability remains after the fix?
We re-check for free. If the hole is still there after you closed it, that's on us.
Do we need an NDA before starting?
Yes, the NDA is signed before any work begins. Client data is never published.

Ready to discuss your project?

Write to us — we'll walk you through it, estimate the scope and name the price.

Telegram: @FzControl OSINT reconnaissance →