Web application penetration testing

Can one account reach another customer’s data?

Authenticated testing of SaaS products and web applications across your agreed roles.

From A$7,500 ex GST for one web app, its API and two user roles.

Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we test

A scope with a purpose.

Identity and access

Sign-in, password recovery, session handling and privilege boundaries.

Tenant and data separation

Object access, exports and file handling between customer accounts.

Business logic

Approval steps, pricing and account changes that should not be bypassed.

Before testing

What we need from you

  • Application URLs and the workflows that matter.
  • A role matrix plus test accounts within and across tenants.
  • Connected APIs named explicitly, not assumed.
Use the scoping checklist
After testing

What you can act on

  • Prioritised application risk by role and workflow.
  • Request or browser evidence for each finding.
  • A practical remediation direction your engineers can follow.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Third-party services and source-code review.
  • Denial of service.
  • Every connected API. Include them deliberately.
  • Production access without written authorisation.
The deliverable

See what you will receive

A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.

See sample report

Questions before you book

Practical answers.

Is staging enough?

A representative staging environment reduces operational risk. We record any difference from production because that difference limits what the result establishes.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Ready to price your test?

The sample report is illustrative, built from synthetic findings. It is not a client report.

Get instant quote

Last reviewed: