Skip to content
Pentesys
Knowledge Base

ApplicationSecurity

Web, API and mobile applications fail in ways scanners do not model well, usually around access control and business logic. These articles cover the vulnerability classes that keep turning up in real assessments, what a tester checks, and what fixes them in code rather than at the perimeter.

All articles

9 articles

Application Security

Mobile Application Penetration Testing

iOS and Android testing beyond the app binary: local storage, certificate pinning, backend APIs and platform-specific weaknesses.

Read article
Application Security

API Penetration Testing

Authorisation flaws, object-level access control and undocumented endpoints. Why API testing needs documentation and credentials to be useful.

Read article
Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.