Security review

We hunt for authorisation, session and input-validation weaknesses on the OWASP Top 10 baseline.

CHECKS
38
DURATION
4–6 business days
PACKAGES
3
TOOLS
Manual testing plus Burp Suite and OWASP ZAP

This does not replace a penetration test; it targets the common and expensive mistakes in the application layer. Authorisation bypass, horizontal and vertical privilege escalation, session handling, insecure direct object references and input validation are the main focus.

From the checklist

38 check items

Authorisation and role checks

Whether another user's record or another role's screen can be reached.

Session and token lifecycle

Whether sign-out, a password change and expiry really end the session.

Input validation and injection

Server-side validation, file upload and query escaping.

Sensitive data exposure

Fields that should not appear in responses, logs or error pages.

DURATION
4–6 business days

How we run it

  1. We map the role matrix: what each role should and should not be able to see.
  2. We push the permission boundaries of every role by hand — horizontal and vertical escalation attempts.
  3. We test the session lifecycle: sign-out, password change, expiry and concurrent sessions.
  4. Input validation, file upload and response bodies get both an automated scan and a manual review.

What you get

  • A finding list mapped onto the OWASP Top 10 categories
  • Request and response capture plus reproduction steps for every finding
  • The role-permission matrix and the deviations we found

Out of scope

  • This is not a penetration test; infrastructure, network and social engineering are out of scope.
  • Source code security review and dependency scanning are separate engagements.
Typical finding mix

What this typically turns up

  • Sessions on other devices survive a password change
  • Changing the order number exposes another customer's invoice
  • The API returns an identity field the interface never shows

Read a sample report

RESPONSE
Within 24 hours

Questions about this service

Does this replace a penetration test?

No. It targets the common and expensive mistakes in the application layer. If regulation requires a pen test report, we will point you to an accredited firm.

Do you need the source code?

Not required — we can work black box. With code access the results improve noticeably, especially on permission checks.

Do you exploit what you find?

Only far enough to prove it exists. We do not exfiltrate data, do not leave changes behind, and log every attempt.

Don't test the next release alongside your users.

Sign up in the panel, pick what you want tested, pay. The first findings start landing in the same panel within hours.

SendTheCanary provides independent software testing for web, mobile and API products. Ten separate services from functional testing to payments and localization, run by a network of 4,700 testers and delivered as one report ranked by severity.