API pentesting
Your API is the part of your product with no interface to hide behind. We test it the way an attacker does, call by call and role by role, with experienced European pentesters and autonomous agents working the same target.
Request pentestWhat API pentesting is
API pentesting is a security assessment of the interface itself, rather than of anything drawn on top of it. Every endpoint, parameter, token and role is attacked under controlled conditions, including the calls your own front end never makes. That is exactly where an attacker starts.
We combine experienced European pentesters with AI-supported tooling. The agents work through the surface at scale, every endpoint against every role, while our specialists chase the flaws that need a person to understand what the calls are for.
What we test
REST, GraphQL, gRPC and the SOAP services still quietly holding a business together. Every endpoint, against every role.
Authentication and tokens
JWT handling and signature validation, OAuth flows, API keys, refresh logic and how long a stolen token stays useful.
Authorization per object
Broken object-level authorization, function-level gaps, role escalation and whether one tenant's identifier reaches another tenant's data.
What comes back
Responses returning more than the screen shows, mass assignment on the way in, and errors that describe your internals with GDPR impact attached.
Rate limits and abuse
Throttling, quotas and lockout, plus the endpoints an attacker can turn into an expense: enumeration, brute force and costly queries.
Business logic
Order, payment and approval calls made out of sequence, replayed, or carrying values no client of yours would ever send.
Configuration and transport
CORS, TLS, HTTP methods, verbose errors, debug routes and old API versions still answering after the new one shipped.
Types of pentest
How much you hand over at the start decides how far a test can go. All three are run by our own pentesters, working with an AI agent set up for that level of access.
Black box
We start with nothing but your address, exactly as a real attacker would. The most realistic test, and usually the shortest list of findings.
What you give us
- Included: Your address or application
- Not included: Test logins and documentation
- Not included: Your source code
Usually done in 3-5 working days
Grey box
You give us a login, so we can test everything your own users can reach. That usually finds considerably more.
What you give us
- Included: Your address or application
- Included: Test logins and documentation
- Not included: Your source code
Usually done in 5-7 working days
White box
You give us the source code as well. Nothing stays hidden, and the report points at the exact lines to fix.
What you give us
- Included: Your address or application
- Included: Test logins and documentation
- Included: Your source code
Usually done in about 2 weeks
How an API test runs
Six stages, from the first call to the retest. At every point you know what is happening and what comes next.
Scoping
We agree the environments, the roles, the test window, the rules of engagement and which endpoints are in scope.
Mapping
We build the full picture of the surface: every endpoint, parameter and version, from your specification and from what the API actually answers.
AI-assisted testing
Our agents run the matrix, every endpoint against every role, while our pentesters work the logic no matrix can describe.
Human validation
Every finding is reproduced and rated by a senior pentester, so what reaches your report is real and nothing else.
Reporting
You receive the findings with the exact request that triggers them, a risk analysis and concrete fixes, alongside a management summary.
Retest
Once your fixes are deployed we replay the same calls, so you know a finding you closed is actually closed.
What you get
A report your developers can work from directly, with a summary the people funding the work can read.
- Every finding with the exact request and response that proves it
- A risk analysis per finding, weighed against real business impact
- Concrete, prioritized fixes written for the people who own the endpoint
- An executive summary that explains the risk in a way anyone can understand
- Findings mapped to the relevant ISO 27001 controls through ARGUS

AssistSec v.s. others
APIs change with every release, which is the problem with testing them once a year and filing the PDF.
| Aspect | Traditional pentest | |
|---|---|---|
| Approach | Agents covering every endpoint against every role, with senior pentesters on the logic | A junior pentester on the test |
| Frequency | Continuous testing that carries on between releases | One snapshot, already out of date by the next deploy |
| Findings | Live in the ARGUS portal, visible the moment something is found | A PDF, weeks after the test ended |
| Retesting | On demand, straight from the portal, at no extra cost | Quoted separately, scheduled again |
| Compliance | Every finding mapped to the relevant ISO 27001 controls | Evidence you assemble yourself |
Frequently asked questions
Which kinds of API do you test?
REST and GraphQL most often, and gRPC, WebSocket and SOAP services just as readily. What matters is not the protocol but whether we can reach it and know which roles are supposed to reach what.
Do you need our OpenAPI specification?
It helps and we will ask for it, along with a Postman collection if you have one. Both let us start on the logic instead of on discovery. Neither is required: we can map the surface from traffic and from the API's own answers, and finding endpoints your specification forgot is often a result in itself.
What do you need from us?
Accounts for each role, ideally two per role so we can test whether one account reaches the other's data, plus a reachable environment and a contact who can answer a question during the test.
Can you test our production API?
Yes, and we regularly do. We agree a test window in advance and treat destructive actions as out of scope unless you explicitly ask for them. If rate limits or noisy monitoring are a concern we work around them, or you point us at an acceptance environment instead.
Does a pentest help with ISO 27001 or NIS2?
A pentest gives you demonstrable evidence for a certification or audit track. Through ARGUS every finding is mapped to the relevant ISO 27001 controls, which makes reporting on your security posture considerably simpler.
Interested in a pentest?
Discover how AI-backed pentesting gives your organization faster and more thorough insight into vulnerabilities.
Contact us

