Web Pentest
Find your vulnerabilities before an attacker does.
Based in Paris, our team conducts penetration tests on your systems, applications and networks to reveal your vulnerabilities and deliver a clear, prioritised remediation plan.
France Cybersecurity Label The web attack surface
A web application is a living surface, not a fixed perimeter
Every endpoint, every parameter, every API call and every user role widens the surface an attacker can probe. Modern frameworks do not neutralise business logic: a missing access check, a tamperable identifier or a bypassable workflow stay invisible to automated tools. Our penetration test draws on the OWASP Top 10, ASVS and WSTG references without being limited to them: we reason as attackers to expose the chains of flaws that lead to a real compromise.
Four families of flaws, tested by hand
Injections and server-side execution
SQL and NoSQL injection, command injection, template injection (SSTI), SSRF and unsafe deserialisation. We look for the points where user input reaches an interpreter, a query or an internal network call without sufficient validation.
Access control and business logic
IDOR/BOLA, horizontal and vertical privilege escalation, workflow bypass. We verify that every object and every action is tied to the authorised user, rather than loaded by identifier with no ownership check.
Authentication and session management
Password weaknesses, JWT token handling, OAuth/OIDC and SSO flows, bypassable MFA. We probe sign-up, login, password reset and session lifetime to surface account takeover paths.
APIs, XSS and data exposure
REST and GraphQL APIs (exposed introspection, field over-exposure, missing rate or query-depth limits), stored, reflected and DOM-based XSS, leakage of sensitive data and secrets in responses, client code or error messages.
Pentest walkthrough
A rigorous methodology, concrete results.
Scoping & preparation
Validation of the scope (URLs, subdomains, environments), exclusions and constraints. Setting up Grey Box access and the test plan.
Mapping & reconnaissance
Building an exhaustive view of the attack surface: pages, endpoints, flows, roles and components. Identification of technologies, authentication mechanisms and open-source intelligence leaks.
Security testing
In-depth manual tests and targeted automation across the full OWASP spectrum: authentication, authorisations, injections, XSS/CSRF, business logic, configuration and, where applicable, AI attacks.
Consolidation & risk assessment
Validation of findings: reproducibility, impact, prerequisites and realistic exploitation scenarios. False positive elimination, root-cause grouping, scoring and prioritisation.
Reporting & deliverables
Closing meeting presenting results, top risks, quick wins and structural recommendations. Delivery of a detailed executive and technical report.
Test types
External penetration test
Conducted from our premises over a standard internet connection, this test assesses the resilience of your internet-facing infrastructure and services against an outside attacker. The objective is to determine whether a remote attacker can compromise your systems without prior access.
- Web applications & API
- Exposed network infrastructure
- Cloud services
- Authentication & remote access
Internal penetration test
Conducted from the client's premises or via an implant deployed on their network, this test simulates an insider threat: malicious employee, phishing-compromised machine, maintenance agent or external consultant. The objective is to assess what an attacker with physical or network access can achieve.
- Active Directory & internal network
- Segmentation & lateral movement
- Workstations & servers
- Privilege escalation
Deliverables
What you receive
At the end of each engagement, you receive complete documentation enabling your technical and management teams to act with precision.
Executive report
Risk summary, overall criticality level and priority recommendations, designed for decision-makers.
Technical report
Full detail of each vulnerability: proof of exploitation, impact, attack scenario and remediation recommendation.
Debrief meeting
Closing meeting presenting findings, Q&A and a prioritised action plan with your teams.
Optional retest
Post-remediation verification of vulnerabilities to confirm the effectiveness of fixes implemented.
Industries
Sector-specific expertise for your business
Pentest for banking and fintech
Credit institutions, neobanks, payment platforms. Our tests cover DORA and PCI-DSS compliance across your sensitive financial applications and flows.
Pentest for healthcare providers
Healthcare data providers, hospitals, medical software vendors. Tests tailored to HDS certification requirements and patient data protection obligations.
Pentest for SaaS and tech startups
Web apps, REST APIs, cloud infrastructure, CI/CD pipelines. We help software vendors validate their security posture ahead of each release.
On-site engagements across France
Our Paris-based team can travel on-site for internal network tests, Red Team missions or debrief sessions with your technical teams.
Frequently asked questions
Web pentest: what to know before you start
How long does a web application pentest take?
Duration depends on scope: the number of endpoints, user roles and sensitive features. A mid-sized application usually requires five to ten days of testing. We calibrate the effort during scoping, once we have counted the user journeys and account types to cover.
Do we need to provide access and source code?
It depends on the chosen approach. In black box, we start with no privileged information. In grey box, the most common approach, you provide test accounts for each role, which lets us cover access control in depth. In white box, access to the source code sharpens the search for flaws. We usually recommend grey box for the best coverage-to-duration ratio.
How is this different from an automated vulnerability scan?
A scanner detects known patterns: outdated versions, missing headers, signatures of published vulnerabilities. It understands neither your business logic nor your authorisation rules, and cannot chain several minor flaws into a full compromise. We use tooling for coverage, then manual exploitation for the IDORs, workflow bypasses and privilege escalations that no scanner finds.
Testing domains
A targeted penetration test for each domain
Mobile, IoT, cloud or LLM: each domain has its own attack surface and methodology.
Pentest Mobile
Find the flaws in your iOS and Android app before an attacker exploits them.
Learn morePentest IoT
Before you ship, find out what an attacker can do with your connected device.
Learn morePentest Cloud
One over-permissive IAM role or an open bucket is enough to compromise your whole cloud.
Learn morePentest LLM
Your LLM applications open an attack surface that your usual tests do not cover.
Learn moreReady to assess your exposure?
Our experts define the scope with you and provide a tailored quote within 48 hours.