ServicesAssessment · advisory · evidence

Web Application Penetration Testing

Independent web application and API penetration testing in Australia — OWASP Top 10, authentication, access control, IDOR and business-logic testing with board-ready reporting.

What we test

OWASP Top 10

Injection, broken access control, authentication flaws and misconfiguration — the full OWASP Top 10, tested by hand.

Authentication & sessions

Login, password reset, MFA, session handling and token security — the controls attackers target first.

Access control & IDOR

Horizontal and vertical privilege checks, and direct-object-reference flaws that expose data belonging to other users.

APIs & integrations

REST and GraphQL APIs, authorisation, rate limiting and the integrations behind your application.

Business logic

Abuse of legitimate features — the flaws no scanner understands but a real attacker will.

Modern front-ends

React, Angular and Vue applications and the APIs that power them.

How we test

We follow the OWASP Web Security Testing Guide, combining authenticated and unauthenticated manual testing with targeted tooling. You receive a board-ready summary, full technical detail with reproduction steps, prioritised fixes and a remediation retest.

Frequently asked questions

Do you test APIs?
Yes — REST and GraphQL APIs are tested for authorisation, injection, rate limiting and data exposure.

Do you test against the OWASP Top 10?
Yes, and beyond it — including the business-logic flaws the Top 10 and automated scanners don’t cover.

Do you perform authenticated testing?
Yes — we test with supplied accounts at each privilege level to surface access-control and IDOR issues.

See also: all penetration testing services · cyber & IT audits.

See what an attacker would find in your application

Book a scoping call and we will define the right test for your web apps and APIs.

Book a Scoping Call    Request a Quote

Indicative pricing — transparent & fixed-fee
Web-application penetration testfrom $7,500

Authorised testing of your web application with verified, exploitable findings, retest and an attestation letter. Final fee confirmed after a short scoping call.

Talk to a senior advisor — confidential, no obligation.

We respond the same business day, Australia-wide. Tell us what you need to secure.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act