Penetration testing for web applications and APIs.

Testing follows real exploit paths and documents impact, reproducible evidence and remediation guidance. Retesting is available separately.

Scope
Product to cloud
Web applications, APIs and supporting cloud paths.
Typical engagement
8–12 consultant days
A fixed fee is provided after scoping.
Delivery
Secure project portal
Temporary, engagement-specific and hosted in the EEA*.

Process and timing

From scope to final report.

Every engagement starts from an authorised perimeter, with objectives, assets, access requirements, exclusions and rules of engagement agreed upfront. A typical engagement lasts around two working weeks: a preliminary report draft after the first week, followed by the final version and a debrief at the end.

  1. Scope

    Perimeter, objectives, assets, roles, access, exclusions and operational constraints agreed before testing starts.

  2. Test

    Testing of real exploit paths, combining automated coverage with senior-tester investigation, reproducible evidence and demonstrated impact.

  3. Report

    An executive summary and technical findings with impact, evidence and reproduction steps.

  4. Optional retest

    After remediation, retesting can be scheduled separately based on the required timeframe and availability.

Perimeter

Technical surfaces and product flows.

OWASP provides a baseline where it fits the scope. Testing then follows the product’s own entry points, trust boundaries, authorisation rules, data flows and integrations.

Engagements are often scoped around enterprise customer assurance, a product or API release, a material infrastructure change, due diligence, or evidence needed within an ISO 27001, SOC 2 or PCI DSS programme. Perspican provides technical assessment evidence; certification, attestation and final compliance decisions remain with the relevant auditor or authority.

Applications and APIs

Auth, authorisation, business logic, data exposure and critical flows.

Cloud and infrastructure

Configurations, exposed services, trust boundaries and escalation paths.

Integrations

Trust relationships, sessions, external services and data handling.

The deliverable

What you receive after the penetration test.

You won’t be left wondering what to do: you get exactly where the issue sits in your code, with a suggested solution.

An executive summary covers exposure and priorities, together with the technical findings needed to reproduce vulnerabilities and plan remediation. Each finding documents:

  • Impact on the product and its data
  • Reasoned severity, with the rationale behind the rating
  • Affected assets and the components involved
  • Reproducible evidence of the behaviour observed
  • Exploitation conditions that have to hold for it to work
  • Reproduction steps your engineers can follow
  • Remediation guidance, with a suggested solution

A preliminary draft lets work begin before final delivery. The debrief clarifies results and priorities, while an optional retest verifies the fixes.

See a sample report

Reports and evidence are shared through a temporary, engagement-specific portal hosted in the EEA*. Data is encrypted in transit and at rest, access and delivery activity is recorded in a time-stamped audit trail, and the portal is removed at the retention point agreed with the client.

* EEA hosting is the default. Another jurisdiction, such as the United States, can be agreed on request, subject to availability and engagement requirements.

Other services

Already have findings, or need what comes after.

When a verified fix requires production code, remediation engineering is available as a scoped add-on.

Common questions

What teams usually ask before testing starts.

What information do you need to scope a penetration test?

Scoping needs the assets and environments in scope, your objectives, required roles and access, exclusions, operational constraints and target dates. These define an authorised perimeter and rules of engagement.

How long does a typical engagement take?

A typical engagement lasts around two working weeks. A preliminary report draft is shared after the first week, followed by the final report and a debrief at the end. The exact schedule is confirmed during scoping.

What does the final report include?

The report includes an executive summary and prioritised technical findings with impact, evidence, reproduction steps and practical remediation guidance.

Is retesting included?

Retesting is optional and scheduled separately after remediation, based on the required timeframe and availability.

Can the assessment support ISO 27001, SOC 2 or PCI DSS?

The assessment can provide technical evidence for customer assurance and ISO 27001, SOC 2 or PCI DSS programmes. It does not itself certify the organisation or guarantee compliance; final decisions remain with the relevant auditor or authority.

How are scanners, AI and client data handled?

Automated harnesses and locally operated open-source models extend coverage and generate hypotheses. A senior tester directs the investigation, validates every reported finding and follows promising signals through real exploit paths. Client data is not submitted to external AI services without prior written approval.

How are reports and evidence delivered?

Each engagement uses an isolated temporary portal on dedicated EEA infrastructure. Reports, evidence and backups are encrypted in transit and at rest, access and delivery activity is recorded in a time-stamped audit trail, and the portal and its data are removed at the agreed retention point. EEA hosting is the default; another jurisdiction, such as the United States, can be agreed on request, subject to availability and engagement requirements.

Let's define the penetration test.

Tell me which assets, environments and dates need to be included.