Skip to content
Tag · 13 posts

#web-app

Operator notes filed under web-app — chronological, newest first.

Analog clock on a night desk next to a laptop and a slim report
Sep 20, 2026 · 6 min

48 hour security review: when the clock actually starts

A 48 hour security review is possible on one web app if access works. The clock starts at login, not at the first sales email or the card charge.

Read post
Abstract API diagram printed beside a laptop and a severity list
Sep 20, 2026 · 6 min

API security review: start with the calls the UI already makes

An API security review for a product team starts with the endpoints the page already calls — missing auth, object access, uploads, and exports.

Read post
Printed assessment table with severity bars next to a laptop
Sep 20, 2026 · 6 min

Application security assessment: the usable version

An application security assessment should rank what a signed-in user can abuse. Here is the scoped version product teams can finish in a week.

Read post
Brass keys, a session checklist, and a faint login glow on a night desk for an authentication security review
Sep 20, 2026 · 6 min

Authentication security review: login is the product

An authentication security review looks at login, reset, invite, roles, and session — the work most web app buyers actually need.

Read post
Signed authorization letter with a gold wax seal on a green leather pad for an authorized web app review
Sep 20, 2026 · 6 min

Authorized web app review: why the permission email matters

An authorized web app review starts with written permission and a URL you own. That is what separates a professional review from reckless scanning.

Read post
Thin stacked printouts of scanner output next to a single ranked report
Sep 20, 2026 · 6 min

Cheap penetration test: when the PDF is just a scanner

Sub-$1,000 full pentest quotes are usually a scanner PDF. Here is how a cheap penetration test differs from a human pass on auth and APIs.

Read post
Two invoice printouts with different names beside one laptop session
Sep 20, 2026 · 6 min

IDOR in a web app review: the finding buyers actually mean

When buyers say IDOR they mean object access that ignores whose record it is. That check belongs in an authorized web app review.

Read post
Redacted sample report with a teal hairline and severity bars
Sep 20, 2026 · 6 min

Sample pentest report: what to demand before you send credentials

A sample pentest report should show severity bars, remediations, and restored state — with no client names and no exploit payloads.

Read post
White access badge on a navy lanyard beside a printed role list for an Entra web app security review
Sep 20, 2026 · 6 min

SSO and Entra in a web app security review

Guest invites beat shared passwords. What to grant a tester on an Entra- or Google-fronted SaaS app without handing over the keys.

Read post
Two printed reports on a desk, one thick binder and one slim ranked list
Sep 20, 2026 · 6 min

Web app pentest vs security review: which one you are buying

Buyers type pentest. Most product teams need an authorized 48-hour review of the live UI, auth, and API. When the longer CREST job is the right spend.

Read post
Two payment envelopes, a brass calculator, and a slim severity report on a night desk for web application security review cost
Sep 20, 2026 · 7 min

Web app security review cost in 2026: what $2,400 actually buys

Most small-app pentest quotes sit between $2,500 and $15,000. Here is what a 48-hour authorized web application security review should include — and what it should not.

Read post
Laptop on a dark desk showing an abstract application, printed notes, brass lamp
Sep 20, 2026 · 6 min

Web application pentest: what you are actually buying

Buyers type web application pentest. Most product teams need an authorized review of the live UI, auth, and API — not a six-week red team.

Read post
Notebook with a severity list beside a laptop showing a login screen
Sep 20, 2026 · 6 min

What is a penetration test for a product team?

A penetration test is authorized hostile use of a system you own. For a SaaS app that usually means the live UI, auth, and API — not a Hollywood red team.

Read post