GreyNod Labs logo

Cybersecurity service

Web Application Security Testing

Authorised testing of a web application to identify vulnerabilities in how it handles users, access, input and data, with clear remediation guidance.

Web application security testing is a focused assessment of one application: how it authenticates users, enforces who can see and change what, handles input, and manages sessions and data.

Depending on the authorised scope, we combine manual testing and verification with automated tools such as Burp Suite, Nmap, Nuclei, OWASP ZAP, Nessus and SQLmap, and other suitable tools. Not every tool is used in every engagement.

Who it is for

  • Businesses that run a web application, customer portal or online store
  • Teams preparing a launch or a major release that want an independent review
  • Organisations that handle customer accounts, orders or personal data online

What is in scope

  • Authentication, session management and account recovery
  • Authorisation and access control
  • Input handling, including injection and cross-site scripting
  • Business-logic issues specific to your workflows
  • Configuration and exposed functionality within the agreed scope

How we work

  1. Agree scope and authorisation. We document the targets, test accounts, timing, limitations and permissions in writing before testing begins.
  2. Test. We test manually and with automated tools within the agreed scope.
  3. Verify. Findings are verified so the report contains confirmed issues rather than unverified tool output.
  4. Report. We deliver a written report and can explain remediation to your developers.

What you receive

  • A written report with an executive summary and technical detail
  • Verified findings with supporting evidence
  • Severity ratings where justified and the potential impact of each issue
  • Remediation recommendations

Limitations

  • Testing covers only the agreed scope and time window.
  • A security assessment reduces risk but cannot guarantee that every vulnerability will be found or that a system will remain secure.
  • Findings reflect the application at the time of testing; later changes are not covered.
  • Retesting is optional and can be agreed separately; it is not automatically included.

What we need from you

  • Written authorisation from the owner of every in-scope asset before testing starts
  • Test accounts for the relevant user roles
  • A named technical contact

Frequently asked questions

Do you test production or staging?

Either can be agreed in the scope. A staging environment that mirrors production is often preferable, and testing windows for production are agreed in advance.

Is this the same as running a vulnerability scanner?

No. Automated tools are part of the work, but findings are verified manually and the report reflects what was actually confirmed.

Is retesting included?

Retesting is optional and can be agreed separately after you have applied fixes.

Ready to talk about your project?

Tell us what you need and we will reply with next steps.

Request a Consultation