Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Applications ]

Web Application Penetration Testing

Manual testing of the application your customers actually log in to.
Typical duration
5-10 days
Starting price
Scoped
You provide
Credentials for each role

[ 01 / The engagement ]

Scanners find reflected XSS. They do not find the checkout flow that lets a user apply a refund twice, or the export endpoint that ignores the tenant ID. We test web applications by hand, role by role, against the OWASP ASVS, and we spend most of the engagement on authorisation and business logic, because that is where the findings that matter live.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

OWASP ASVSOWASP Top 10OWASP WSTG
  1. 01Full OWASP Top 10 coverage, tested rather than scanned
  2. 02Broken access control across every role boundary
  3. 03Injection: SQL, NoSQL, command, template and LDAP
  4. 04Cross-site scripting, including DOM and mutation-based
  5. 05SSRF, XXE and unsafe redirect chains
  6. 06Client-side logic, CSP and third-party script exposure
  7. 07Password reset, MFA enrolment and account recovery flows

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ 04 / Questions ]

Before you commit.

By roles, authenticated page count and the number of distinct workflows, not by lines of code. A short call is usually enough for us to put a fixed number in writing.

Yes. One retest of every confirmed finding is included for 90 days after the report, and it does not need a new purchase order.

Scope a web application penetration testing.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.