Vulnerability assessment
Identifying weaknesses in your application, configuration and dependencies, then confirming them manually.
How we test, how we build, and how to report a vulnerability to us.
Security testing should make systems safer without putting them, or the people who use them, at risk.
We test only with explicit written authorisation from the system owner, within an agreed scope and time window. We never test third-party systems without their owner's permission, and we don't use destructive techniques.
Our methodology follows the OWASP Top 10, the OWASP Application Security Verification Standard (ASVS) and the OWASP Web Security Testing Guide.
Identifying weaknesses in your application, configuration and dependencies, then confirming them manually.
Login, password reset, multi-factor and OTP flows, and account enumeration.
Access control, IDOR/BOLA, and horizontal and vertical privilege escalation.
Session expiry, logout, fixation, and cookie attributes such as Secure, HttpOnly and SameSite.
Cross-site scripting, injection, path traversal and server-side request forgery, using non-destructive payloads.
Authentication, authorisation, rate limiting, CORS, HTTP methods, error handling and data exposure.
We welcome reports from security researchers. Report it privately, give us time to fix it, and we'll credit you in our Hall of Fame. We won't take legal action against researchers who follow our disclosure rules.