Web penetration testing, done the way an attacker would
Grey-box security testing for web apps and APIs in Zimbabwe and beyond: sign-in, sessions, the API, the data and who can reach it, with a report your developers can act on.
Apps break in four places: the sign-in, the API, the data and who is allowed to reach it. Code written quickly, or written by AI tools, opens those gaps faster than most teams can review them. We test all four before someone else does.
We test with a normal user account, the way a real attacker usually starts, and work through the OWASP Top 10. Every finding is rated by CVSS severity, shown step by step so your team can reproduce it, and paired with the fix. Once you have fixed them, we test again.
- Schools and universities with student and staff portals
- Businesses taking payments or personal data online
- Teams about to launch, or just after a big release
- Anyone asked for a security review by a client or a partner
Passwords, resets, tokens, sessions and every form a user can type into.
Each endpoint asked who is calling and what they may see, including the ones the app never calls.
What you store, how it is encrypted and who can read it.
Admins, staff, teachers and students, each held to their own role, and nobody able to step into another's.
Each finding rated by CVSS severity, with the steps to reproduce it and how to fix it.
When your fixes are in, we test those findings again and confirm what is closed.
A short call, a fixed quote, then the work
We learn who it is for, what it must do and when you need it.
Scope, price and dates in writing, from the starting prices above.
In the open: you see it take shape, on your own devices.
We ship it to the stores or the web, and stay on for fixes and changes.
- Certified Offensive Security Explorer (COSE), 2025
- M.Sc. in Information Security, 2026
- Penetration test for Gazinformservice LLC, 2025
Will testing break our site?
Testing can disturb a system, so we agree the times and limits with you first and stay inside them. For a site in daily use we can test a copy instead.
What do you need from us?
Written permission from the owner of the system, the scope and dates we agree, and a normal user account for each role we test.
What is in the report?
Every finding, rated by CVSS severity, with the steps to reproduce it and how to fix it, plus a short summary for whoever signs off the work.
Is a retest included?
Yes. Once your team has made the fixes, we test those findings again and tell you which are closed.
Who sees the findings?
Only you. Findings are confidential, and we report them to no one else.
How is the price set?
The price on this page is where the work starts. After a short call we send a written quote with the scope, price, dates and what you will receive. It holds for 30 days.
How do we pay?
In US dollars unless the quote says otherwise: a deposit before work starts and the balance on delivery. Invoices are due within 14 days.
Tell us what you need tested or built
We reply within one business day, on WhatsApp or by email.