Website quick scan
A fast external check of your website, without logging in, using tools and manual review. You receive a short report in plain language with what you can improve straight away.
What I check
- HTTPS/TLS settings and security headers
- Visible software and versions (such as CMS and plugins), compared against known vulnerabilities
- Publicly reachable admin pages, files and folders that should not be online
- Cookie settings and your domain’s SPF, DKIM and DMARC, against misuse of your email address
A quick scan gives breadth: the weak spots an attacker also sees first. To learn what is possible behind your login, a web pentest is the next step.
API quick scan
A fast external check of your API, without logging in. You receive a short report with the main risks and what to do about them.
What I check
- Whether API documentation (such as Swagger or OpenAPI) is unintentionally public
- Which endpoints respond without authentication and what they return
- HTTPS/TLS, CORS settings and error messages that reveal too much
- Whether there is a limit on the number of requests
The biggest API risks often sit in permissions between users: can customer A request customer B’s data? I test that in an API pentest.
Web pentest
A hands-on test of your web application, the way an attacker would approach it, following OWASP guidance. Includes a report, a debrief and one retest.
What I test
- Login, password reset and sessions
- Access rights: can a user reach data or functions that are not meant for them?
- Input and uploads, such as SQL injection and cross-site scripting (XSS)
- Your application’s logic, such as orders, payments or discounts
Black-box or grey-box, your choice. Black-box shows what an outsider without prior knowledge can do. Grey-box, with test accounts, goes deeper in the same time. I help you choose.
API pentest
A hands-on test of your REST or GraphQL API following the OWASP API Security Top 10. Includes a report, a debrief and one retest.
What I test
- Permissions per object and per user: can customer A reach customer B’s data?
- Authentication, tokens and sessions
- Excessive data in responses and fields that should not be editable
- Abuse of functions and missing limits
Black-box or grey-box, your choice. For an API, grey-box, with test accounts and documentation, usually yields the most findings per hour.
Cybersecurity advice
Independent advice to protect your business better.
How I help
- Before a pentest: what should you test, and how? After it: what do you fix first?
- An assessment of the security of your website, application or settings (security review)
- A security policy and an incident response plan: who does what when things go wrong
- Awareness training: learning to recognise phishing and other traps