Service 02, included in your subscription
API security testing
We test APIs as first-class attack surfaces, using documentation, captured traffic and role-aware testing to expose authorisation, data and abuse paths.
What we test
Object authorisation
BOLA, IDOR and broken ownership checks across tenants and roles.
Authentication & tokens
JWT handling, session expiry, refresh flows and weak claims validation.
Data exposure
Over-broad responses, sensitive fields and unsafe object expansion.
Rate limiting
Resource exhaustion, brute force windows and GraphQL batching abuse.
Input handling
Injection, SSRF, parameter pollution and mass assignment.
API inventory
Legacy endpoints, undocumented methods and versioning gaps.
What you get
A report your auditor and your engineers both understand
Executive summary, per-finding reproduction steps, severity-rated remediation guidance and retesting included once you have fixed the issue.
Book a callFAQ
Common questions
Do you need API documentation?
Documentation helps, but it is not mandatory. We can test from OpenAPI specs, Postman collections, GraphQL schemas or captured traffic.
Can you test GraphQL APIs?
Yes. We test schema exposure, batching, query depth, resolver behaviour and object authorisation specific to GraphQL.
Can API testing fit into a release cycle?
Yes. We can test a defined release candidate and retest high-risk fixes before launch.