Applications and APIs
Auth, authorisation, business logic, data exposure and critical flows.
Testing follows real exploit paths and documents impact, reproducible evidence and remediation guidance. Retesting is available separately.
Process and timing
Every engagement starts from an authorised perimeter, with objectives, assets, access requirements, exclusions and rules of engagement agreed upfront. A typical engagement lasts around two working weeks: a preliminary report draft after the first week, followed by the final version and a debrief at the end.
Perimeter, objectives, assets, roles, access, exclusions and operational constraints agreed before testing starts.
Testing of real exploit paths, combining automated coverage with senior-tester investigation, reproducible evidence and demonstrated impact.
An executive summary and technical findings with impact, evidence and reproduction steps.
After remediation, retesting can be scheduled separately based on the required timeframe and availability.
Perimeter
OWASP provides a baseline where it fits the scope. Testing then follows the product’s own entry points, trust boundaries, authorisation rules, data flows and integrations.
Engagements are often scoped around enterprise customer assurance, a product or API release, a material infrastructure change, due diligence, or evidence needed within an ISO 27001, SOC 2 or PCI DSS programme. Perspican provides technical assessment evidence; certification, attestation and final compliance decisions remain with the relevant auditor or authority.
Auth, authorisation, business logic, data exposure and critical flows.
Configurations, exposed services, trust boundaries and escalation paths.
Trust relationships, sessions, external services and data handling.
The deliverable
You won’t be left wondering what to do: you get exactly where the issue sits in your code, with a suggested solution.
An executive summary covers exposure and priorities, together with the technical findings needed to reproduce vulnerabilities and plan remediation. Each finding documents:
A preliminary draft lets work begin before final delivery. The debrief clarifies results and priorities, while an optional retest verifies the fixes.
Reports and evidence are shared through a temporary, engagement-specific portal hosted in the EEA*. Data is encrypted in transit and at rest, access and delivery activity is recorded in a time-stamped audit trail, and the portal is removed at the retention point agreed with the client.
* EEA hosting is the default. Another jurisdiction, such as the United States, can be agreed on request, subject to availability and engagement requirements.
Other services
Validate scanner, AI and previous assessment findings against the real code, then make the fix practical.
Review a sensitive change, work through a remediation or verify a fix without repeating a full pentest.
When a verified fix requires production code, remediation engineering is available as a scoped add-on.
Common questions
Scoping needs the assets and environments in scope, your objectives, required roles and access, exclusions, operational constraints and target dates. These define an authorised perimeter and rules of engagement.
A typical engagement lasts around two working weeks. A preliminary report draft is shared after the first week, followed by the final report and a debrief at the end. The exact schedule is confirmed during scoping.
The report includes an executive summary and prioritised technical findings with impact, evidence, reproduction steps and practical remediation guidance.
Retesting is optional and scheduled separately after remediation, based on the required timeframe and availability.
The assessment can provide technical evidence for customer assurance and ISO 27001, SOC 2 or PCI DSS programmes. It does not itself certify the organisation or guarantee compliance; final decisions remain with the relevant auditor or authority.
Automated harnesses and locally operated open-source models extend coverage and generate hypotheses. A senior tester directs the investigation, validates every reported finding and follows promising signals through real exploit paths. Client data is not submitted to external AI services without prior written approval.
Each engagement uses an isolated temporary portal on dedicated EEA infrastructure. Reports, evidence and backups are encrypted in transit and at rest, access and delivery activity is recorded in a time-stamped audit trail, and the portal and its data are removed at the agreed retention point. EEA hosting is the default; another jurisdiction, such as the United States, can be agreed on request, subject to availability and engagement requirements.
Tell me which assets, environments and dates need to be included.
Prefer to write directly? [email protected]