Web application security
Manual and tool-assisted testing of application behavior, exposed functionality, input handling, state transitions, and security controls.
Services
Assessment depth and techniques are defined during scoping. The categories below describe our intended specialization—not an automatic claim that every technique applies to every engagement.
Manual and tool-assisted testing of application behavior, exposed functionality, input handling, state transitions, and security controls.
Object- and function-level authorization, authentication, schema and endpoint behavior, sensitive actions, rate/abuse controls, and business logic.
Cross-tenant access, role boundaries, organization membership, invitations, administrative actions, object ownership, and tenant-scoped data flows.
Registration, login, session lifecycle, MFA, recovery, tokens, role transitions, account linking, and privilege boundaries.
Prompt and context boundaries, RAG isolation, sensitive output, indirect prompt injection, tool authorization, and agent action controls.