Skip to content
Cyber Defence

Manual Web Security Test

Hands-on security testing of your web application with proof-of-concept evidence for every finding and a free retest after you fix issues.

12 working days₹32,999 incl. GST7 deliverables
Overview

What this service covers

Automated scanners find the easy issues and miss the expensive ones, such as changing an ID in the URL and seeing another customer's invoices. Our team tests manually against the common classes of web application vulnerability and against your specific business logic, working as an attacker with a legitimate login. Access control is checked for every role. Each finding comes with a CVSS rating, reproduction steps and evidence, so developers can act immediately. You also get a plain-language summary, tailored remediation advice, a free retest within 30 days and a summary letter to share with customers.

Deliverables

What you receive

  • Manual testing of login, permissions and business logic
  • Coverage of common web vulnerability classes plus API-specific checks
  • CVSS scores, reproduction steps and supporting evidence for each issue
  • Access control tested for every user role in your product
  • A plain-language summary for non-technical readers
  • Fix guidance specific to your systems rather than generic advice
  • A free retest within 30 days and a summary letter for customers
How it runs

The work in 4 stages

  1. Stage 1: Agree limits

    We confirm the targets, user roles, test logins and rules for testing.

  2. Stage 2: Attack

    Several days of manual testing, with critical issues flagged at once.

  3. Stage 3: Write up

    Each issue is documented with evidence and fix guidance.

  4. Stage 4: Check fixes

    Once you have made changes we confirm each fix and revise the report.

Fit and inputs

Who it suits, and what we need from you

Ideal for

  • Products handling payment, health or personal data
  • Businesses asked by a large customer for a security test report
  • Teams that have never had an independent review

What we need from you

  • Test logins for each role, on staging or a near-production copy
  • Written permission to test from someone with authority to give it
  • A developer who can respond quickly to a critical issue

You share these through the brief on your order page after checkout.

Why it helps

What changes for your team

  • Vulnerabilities found and fixed before attackers find them
  • A report suitable for customers or auditors
  • Fixes verified, not simply assumed
Questions

Questions about this service

We prefer staging. If live testing is necessary, we agree tight limits and timings, and no destructive tests are run.

Yes. Its layout matches what auditors and corporate security reviewers look for in SOC 2 and ISO 27001 work and in customer due diligence.

You get that result in writing, which is valuable evidence for customers and auditors on its own.

This is a remote service: nothing is shipped physically, and the work is delivered into systems you control. See delivery and handover and refunds and cancellation for the full terms.

Related services

Often considered alongside this one

All Cyber Defence