Web & API Penetration Testing
Manual web & API penetration testing that finds what scanners miss.
Automated tools catch the obvious. AMATAS web and API penetration testing goes further — our testers think like attackers, chaining vulnerabilities, probing business logic, and exploiting the gaps between your systems to show you what real-world impact looks like.
- CREST-accredited
- OWASP Top 10 coverage
- DORA & NIS2 aligned
- Remediation testing included
Web applications and APIs are the most targeted entry point for attackers — and the most complex to secure. Every new feature, integration, or API endpoint expands your attack surface.
AMATAS conducts manual-first penetration testing using the same techniques adversaries use: mapping authentication flows, testing access controls across roles, probing API endpoints for excessive data exposure, and chaining minor weaknesses into critical attack paths. The result is a clear, risk-ranked picture of your exposure – not just a list of CVEs from a scanner.
Test coverage
What we test in every web & API engagement
Authentication & session management
Login bypass, session fixation, token predictability, multi-factor authentication weaknesses, and credential stuffing exposure.
Authorisation & access control
Broken object-level authorisation (BOLA/IDOR), privilege escalation, horizontal and vertical access control bypass.
Injection vulnerabilities
SQL, NoSQL, LDAP, command, and template injection across all input vectors – parameters, headers, cookies, and API payloads.
API-specific vulnerabilities
Excessive data exposure, mass assignment, rate limiting bypass, API versioning weaknesses, and GraphQL introspection abuse.
Business logic flaws
Workflow bypasses, price manipulation, race conditions, and application-specific logic that automated tools cannot discover.
Client-side security
Cross-site scripting (XSS), cross-site request forgery (CSRF), clickjacking, subresource integrity, and Content Security Policy effectiveness.
What you receive
Deliverables from every engagement

Technical report
Risk-ranked findings with CVSS scores, reproduction steps, evidence, and step-by-step remediation guidance for your developers.

Executive summary
A non-technical overview of your risk exposure, key findings, and recommended priorities – ready to share with leadership and the board.

Attack path map
Visual representation of how individual vulnerabilities chain together to form realistic attack paths across your environment.

Remediation testing & certificate
After you remediate findings, we retest at no extra cost and issue a signed certificate of completion for audit and compliance purposes.
Compliance support
Regulatory frameworks this service supports
Our web & API penetration testing reports are structured to provide the evidence required by auditors across various frameworks, including:
- DORA
- NIS2
- OWASP Top 10
- ISO 27001
- PCI DSS
- HIPAA
Test coverage
Choose the right level of testing
Every organization has different security needs, budgets, and compliance obligations. Our three service tiers are designed to match your context:

- Deep, CREST-certified testing that simulates real-world, multi-layered attacks
- Led by senior testers using advanced exploitation methods
- Detailed reports, attack path mapping, and remediation validation
- Best for enterprises and regulated industries

- Fast, affordable testing for quick vulnerability discovery and compliance validation
- Combines automated scans with manual expert review
- Concise, actionable reports aligned with ISO 27001, DORA, NIS2, and GDPR
- Best for SMEs seeking cost-efficient assessments

- AI-driven continuous testing and validation via the Plainsea platform for 24/7 protection
- Merges automation with ongoing expert oversight
- Live dashboards, historical tracking, and continuous compliance updates
- Best for organizations needing always-on assurance
FAQ
Web & API penetration testing - common questions
Timelines vary by scope. An Essential engagement covering a single application typically takes 3-5 days. An Elite engagement covering complex applications with multiple APIs may take 2–3 weeks. We agree on a specific timeline during scoping based on the number of targets, authentication complexity, and your compliance requirements.
We always agree on rules of engagement before testing begins. We can test against production, staging, or a dedicated test environment depending on your risk tolerance. For production environments, we conduct testing in a way that minimizes service disruption – and we maintain a communication channel throughout so any unexpected impact can be addressed immediately.
Yes – we test REST, GraphQL, SOAP, and gRPC APIs. GraphQL testing specifically includes introspection abuse, query depth attacks, batching attacks, and authorization bypass across nested objects. We work from API documentation or schema files where available, and conduct unauthenticated discovery where not.
Essential testing uses a combination of automated tooling with expert validation – ideal for compliance-driven engagements where speed and cost efficiency matter. Elite testing is a fully manual, expert-led engagement with deeper business logic testing, attack path simulation, and exploitation of chained vulnerabilities. Elite is recommended for critical systems, regulated industries, and organisations with higher risk profiles.
Yes — AMATAS is a CREST-accredited company for penetration testing services. CREST accreditation means our processes, methodologies, and quality controls meet the internationally recognized standard for penetration testing. This is particularly relevant for clients in regulated sectors where CREST-accredited providers are required or strongly preferred.
Ready to see what's exposed?
Talk to our team – we’ll scope the right penetration testing for your web applications and APIs.
Often combined with Web & API testing

Mobile App Penetration Testing
Extend coverage to your iOS and Android applications and the APIs they depend on.

Vulnerability Assessment
Continuous scanning that keeps known weaknesses in check between penetration tests.
Source Code Review
Find the vulnerabilities in your codebase before they’re exploitable in the running application.