ZW-Labs · Penetration testing
Every way in.
We try it first.
Hands-on testing of the systems your business runs on. Every finding comes with evidence and a specific fix, and we retest once you've fixed it.
We test the app your customers log in to, across every role, the way someone who wants their data would.
What we look at
- Authorisation between roles and between tenants
- Login, session and password-reset flows
- Injection of every kind: SQL, template, command, header
- Business logic specific to how your product works
- File upload, SSRF and deserialisation
Any signed-in customer can read any other customer's invoices
Mapped to
- OWASP ASVS
- OWASP Top 10
- SOC 2
- ISO 27001
- PCI DSS
How it runs
Scope, test, report, retest.
Nothing is touched until scope and written authorisation are agreed.
Before we start
Scope
We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.
During the test
Test
Hands-on testing. Anything critical comes to you the day we find it, not in the final report.
When testing ends
Report
An executive summary for leadership, and every finding with evidence, severity and a specific fix.
When you're ready
Retest
We verify each fix and reissue the report showing what's closed — ready for auditors and customers.
Questions
Before you book.
How long does a test take?Open +
It depends on scope. A focused web or API test is usually one to two weeks of testing. You get a timeline with the proposal, before anything is agreed.
What do you need from us?Open +
What's in scope, test accounts where relevant, a testing window, and a signed authorisation. We send a short scoping questionnaire to make it quick.
Will it affect production?Open +
We agree the environment and any excluded actions first. A staging copy of production is preferred; where we must test production, destructive checks are excluded or scheduled with you.
Can the report support SOC 2, ISO 27001, PCI DSS or HIPAA?Open +
Yes — it's structured to serve as independent testing evidence. Certifying compliance is your auditor's job; we give them what they need from a test.
Tell us what needs testing — or watching.
Get a quote →