Services / VAPT

Hands-on testing of your web apps, APIs, mobile apps and networks. Every finding is reproduced, rated and comes with a fix.

A scanner lists what might be wrong. A penetration test proves what is. We use automated discovery to cover the ground, then test by hand for the flaws that tools miss: broken access control between users and roles, injection, and abuse of your business logic.

Each finding in the report shows exactly how it was exploited, what an attacker gains, and what to change to fix it.

repeater — invoices
GET /api/v1/invoices/7731 HTTP/1.1Host: app.example.testAuthorization: Bearer ‹customer_b› HTTP/1.1 200 OK{ "id": 7731, "owner": "customer_a", "total": 48200 } ✕ another customer's invoice · IDOR · High 8.1
When you need this
  • Before a major release or a new product goes live
  • A client or partner has asked for a recent VAPT report
  • An audit or certification needs independent security testing
  • After significant changes to authentication, roles or payments
Coverage

What we test

The exact scope is agreed in writing before we start. This is what a typical engagement covers.

01

Web applications

  • Login, session and password-reset flows
  • Access control between users, roles and tenants (IDOR)
  • Injection: SQL, NoSQL, command and template
  • Cross-site scripting, CSRF and SSRF
  • File upload and download handling
  • Business logic: skipped steps, tampered prices and quantities
02

APIs (REST & GraphQL)

  • Object- and function-level authorisation
  • Token handling, including JWT validation and expiry
  • Mass assignment and excessive data exposure
  • Rate limiting, enumeration and brute force
  • OWASP API Security Top 10
03

Mobile apps

  • Sensitive data stored on the device
  • Transport security and certificate pinning
  • Secrets and keys embedded in the app
  • The backend APIs the app talks to
04

Networks

  • External attack surface: exposed services and ports
  • Software with known CVEs
  • Weak protocols, ciphers and default credentials
  • Internal segmentation and lateral movement
Deliverables

What you receive.

  • Executive summary of overall risk for leadership
  • Findings ranked by CVSS severity, adjusted for your business context
  • Steps to reproduce and request/response evidence for every finding
  • Specific remediation guidance, not generic advice
  • Retest report showing the status of each finding after your fixes
Standards we work to
  • OWASP WSTG
  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP MASVS
  • PTES
  • NIST SP 800-115
  • CVSS
Before we start

What we need from you

  • Signed authorisation covering the targets and testing dates
  • Test accounts for each role you want tested (grey-box testing finds far more than black-box)
  • A staging environment that mirrors production, or agreed testing windows on production
  • Allow-listing of our source IPs if a WAF or rate limiter sits in front
  • A technical contact who can answer questions during testing

Never send passwords or keys by email. We set up a secure channel once the scope is agreed.

Often combined with

Related services.

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope