Offensive security

    Web Application Security Testing

    Test the application the way an attacker uses it.

    Manual, authenticated security testing of web applications — business logic, access control, session handling and injection classes.

    Test sequence

    Scope: Roles, environments, test data and rules of engagement.

    A web application security assessment is a manual penetration test of a running web application. Automated scanners find known patterns; our testers work through the application with real user roles to find broken access control, flawed business logic and authorisation gaps that scanners structurally cannot detect. Testing follows the OWASP Testing Guide and is mapped to the OWASP Top 10, so results are comparable and auditable.

    • Manual testing by OSCP/OSWE-certified testers, not a scanner report with a cover page.
    • Every finding rated by exploitability and business impact, with reproduction steps.
    • One free retest of remediated findings included within the engagement window.

    How this service connects

    This assessment is a focused form of penetration testing for running web applications.

    Where the application exposes substantial backend interfaces, add dedicated API Penetration Testing for every endpoint, role and object boundary.

    Between manual tests, Vulnerability & Threat Assessment helps maintain a prioritised view of exposure.

    Who should consider this assessment

    • Startups establishing a secure foundation for a new web application.
    • Growing businesses operating customer portals or applications with multiple roles.
    • Enterprises running e-commerce, SaaS or other business-critical web platforms.

    What you receive

    1. 01A technical report with evidence, reproduction steps and developer-focused remediation guidance.
    2. 02An executive summary that explains business impact and supports risk-based prioritisation.
    3. 03A verification retest of remediated findings within the agreed engagement window.

    Service packages

    Starter Package

    Who it is for
    Small or simple web applications with limited features.
    Scope
    Up to 10 pages, minimal APIs and basic authentication mechanisms.
    Ideal for
    Startups, personal websites and single-purpose applications.

    €1,500 excl. VAT

    Configure with our team

    Standard Package

    Who it is for
    Medium-sized web applications with moderate complexity.
    Scope
    Up to 50 pages, multiple APIs and complex role-based authentication.
    Ideal for
    Mid-size businesses, customer portals and multi-functional applications.

    €3,600 excl. VAT

    Configure with our team

    Enterprise Package

    Who it is for
    Large-scale or enterprise-grade web applications.
    Scope
    Unlimited pages, extensive APIs, third-party integrations and advanced authentication.
    Ideal for
    E-commerce platforms, SaaS solutions and mission-critical applications.

    Custom scope

    Configure with our team

    Expertise and delivery standards

    Certified offensive-security expertise

    Our experts hold certifications including OSEE, OSCP, OSWE, OSEP, OSED, OSWP, eWPTx, eMAPT, eCPPT, CRTO and CEH.

    ISO 9001 & ISO 27001

    Evolvice operates certified quality-management and information-security systems under ISO 9001:2015 and ISO 27001:2022.

    13+ years in IT delivery

    More than thirteen years of technology delivery inform scoping, communication, reporting and remediation support.

    Their penetration testing report was not only detailed but actionable. Our developers could immediately start fixing the issues.
    They helped us identify critical vulnerabilities we didn’t know existed. A truly professional and responsive team.
    From the initial scoping call to the final report, everything was handled with precision and professionalism.

    What the engagement covers

    01

    Broken access control

    Horizontal and vertical privilege testing across every user role and tenant boundary.

    02

    Business logic flaws

    Workflow abuse, price and quantity manipulation, state and sequence bypasses.

    03

    Injection classes

    SQL, NoSQL, command, template and XSS testing against real application behaviour.

    04

    Authentication & sessions

    Login, MFA, password reset, token lifetime and session invalidation.

    05

    Server-side weaknesses

    SSRF, insecure deserialisation, file upload handling and misconfiguration.

    06

    Third-party components

    Vulnerable dependencies assessed in the context of your application, not in isolation.

    Q&A

    How long does a web application test take?

    A typical business application takes five to ten working days of testing, depending on the number of roles and the size of the functional surface. Scope is agreed before the engagement starts.

    Do you test in production or in staging?

    Staging is preferred when it mirrors production. Production testing is possible under agreed rules of engagement, defined windows and escalation contacts.

    What do we receive at the end?

    A technical report with reproduction steps and fix guidance, an executive summary for decision-makers, and a retest of remediated findings.

    How does this differ from a vulnerability scan?

    A scan matches known signatures. This is manual testing that chains findings together and proves real exploitability — including logic flaws a scanner cannot see.

    Let us look at your current security position first.