Cybersecurity service
API Security Testing
Authorised testing of APIs for authentication, authorisation, data-exposure and input-handling weaknesses.
APIs expose application logic and data directly, so a single missing check can expose many records. API security testing looks at how each endpoint authenticates callers, authorises each request and validates input.
Depending on the authorised scope, we combine manual testing and verification with automated tools such as Burp Suite, Nmap, Nuclei, OWASP ZAP, Nessus and SQLmap, and other suitable tools. Not every tool is used in every engagement.
Who it is for
- Businesses with public, partner-facing or mobile-app APIs
- Web applications and single-page apps backed by an API
- Teams integrating with third-party services
What is in scope
- Authentication and token handling
- Object-level and function-level authorisation
- Excessive data exposure
- Input validation and injection
- Abuse resistance such as missing rate limits, where in scope
How we work
- Review the API. We study the documentation or observed behaviour to understand intended use, and agree scope and authorisation in writing.
- Test. We test each role against the endpoints in scope, manually and with suitable tools.
- Verify and report. We verify findings and document them with evidence and remediation recommendations.
What you receive
- A written report with verified findings and supporting evidence
- Example requests and responses where they help reproduction
- Potential impact, severity where justified, and remediation recommendations
Limitations
- Only the endpoints and environments in the written scope are tested.
- Third-party APIs you do not own are out of scope unless their owner authorises testing in writing.
- Load and performance testing are not part of this service.
- A security assessment reduces risk but cannot guarantee that every vulnerability will be found or that a system will remain secure.
- Retesting is optional and can be agreed separately; it is not automatically included.
What we need from you
- Written authorisation from the owner of every in-scope asset before testing starts
- API documentation or a collection of requests, if available
- Test credentials for the roles in scope
Frequently asked questions
Do you need our API documentation?
It improves coverage and saves time, but testing can also be based on observed behaviour if documentation is missing.
Can you test the API of a service we do not own?
Only with written authorisation from the owner of that service.
Ready to talk about your project?
Tell us what you need and we will reply with next steps.

