Skip to content
Use our free scanner to check your security!

Web application pentesting

Find vulnerabilities before attackers do. AssistSec combines experienced pentesters with autonomous AI agents to test web applications and APIs faster, wider and more consistently. Every finding is validated by an expert and comes with a clear, direct recommendation, made visible in your customer portal.

Request pentest

What web application pentesting is

Web application pentesting is a security assessment in which your application is attacked under controlled conditions, exactly as a real attacker would, but ending in a report instead of an incident. Everything a user can reach is in scope: the login, the roles behind it, the data each account can touch and the business logic tying it all together.

We combine experienced European pentesters with AI-supported security tooling. The agents cover the breadth of the application while our specialists chase the findings that need human judgment.

What we test

We test with autonomous AI agents, following the OWASP Top 10 and PTES.

  • Authentication and sessions

    Login flows, multi-factor authentication, password reset, session handling and how long a token stays valid.

  • Authorization and access control

    Broken access control, IDOR, privilege escalation and whether one customer can reach another customer's data.

  • Injection and input handling

    SQL injection, cross-site scripting, template and command injection, and everything else that follows unvalidated input.

  • Business logic

    Order flows, pricing, quotas and approval steps, abused in ways an automated scanner never finds.

  • Configuration and hardening

    Security headers, TLS, exposed admin interfaces, verbose error messages and outdated components.

  • Data exposure

    Personal data reachable without authorization, API responses that give away too much, and information disclosure with GDPR impact.

Types of pentest

How much you hand over at the start decides how far a test can go. All three are run by our own pentesters, working with an AI agent set up for that level of access.

  • Black box

    We start with nothing but your address, exactly as a real attacker would. The most realistic test, and usually the shortest list of findings.

    What you give us

    • Included: Your address or application
    • Not included: Test logins and documentation
    • Not included: Your source code

    Usually done in 3-5 working days

  • Grey box

    You give us a login, so we can test everything your own users can reach. That usually finds considerably more.

    What you give us

    • Included: Your address or application
    • Included: Test logins and documentation
    • Not included: Your source code

    Usually done in 5-7 working days

  • White box

    You give us the source code as well. Nothing stays hidden, and the report points at the exact lines to fix.

    What you give us

    • Included: Your address or application
    • Included: Test logins and documentation
    • Included: Your source code

    Usually done in about 2 weeks

How a pentest runs

Six stages, from the first call to the retest. At every point you know what is happening and what comes next.

Where it starts
  1. Scoping

    We agree the scope, the test window and the rules of engagement, and decide together whether the test is blackbox or greybox.

  2. Reconnaissance

    We map the full attack surface: endpoints, parameters, roles and the technology stack behind them.

  3. AI-assisted testing

    Our autonomous agents work through the application while our pentesters follow the leads that need human judgment.

  4. Human validation

    Every finding is reproduced and rated by a senior pentester, so what reaches your report is real and nothing else.

  5. Reporting

    You receive the findings with evidence, a risk analysis and concrete recommendations, alongside a management summary.

  6. Retest

    Once your fixes are live we verify them, so you know a finding you closed is actually closed.

What you get

Every test closes with a professional report that works for your developers and your board at the same time.

  • Every finding with reproduction steps and evidence
  • A risk analysis per finding, weighed against real business impact
  • Concrete, prioritized recommendations your developers can act on
  • An executive summary that explains the risk in a way anyone can understand
  • Findings mapped to the relevant ISO 27001 controls through ARGUS
A sample AssistSec pentest report, open at the executive summary, with the technical appendix half-visible behind it

AssistSec v.s. others

The same test, delivered the way security actually works now: continuously, in the open, and with the people who found the issue reachable while you fix it.

AssistSec compared with a traditional penetration test
AspectTraditional pentest
ApproachSenior European pentesters and autonomous agents on the same targetA junior pentester on the test
FrequencyContinuous testing that carries on between pentestsOne snapshot, once a year
FindingsLive in the ARGUS portal, visible the moment something is foundA PDF, weeks after the test ended
RetestingOn demand, straight from the portal, at no extra costQuoted separately, scheduled again
ComplianceEvery finding mapped to the relevant ISO 27001 controlsEvidence you assemble yourself

Frequently asked questions

What is the difference between blackbox and greybox testing?

In a blackbox test we start with nothing more than a URL, exactly like an outside attacker. In a greybox test you give us accounts and, if you want, documentation or source access, so we reach the deeper layers of the application within the same amount of time. Most organizations get more out of greybox.

How long does a pentest take?

That depends on the size of your application and the number of roles in it. We determine the effort during scoping and put it in writing before we start, so the scope and the price are agreed up front.

Can you test our production environment?

Yes, and we regularly do. We agree a test window in advance and treat destructive actions as out of scope unless you explicitly ask for them. If you would rather we work on an acceptance environment, that works too.

Do you help fix the findings as well?

You get concrete recommendations for every finding, and we are happy to walk your developers through them. Once a fix is live we retest it, so you know it holds.

Does a pentest help with ISO 27001 or NIS2?

A pentest gives you demonstrable evidence for a certification or audit track. Through ARGUS every finding is mapped to the relevant ISO 27001 controls, which makes reporting on your security posture considerably simpler.

Interested in a pentest?

Discover how AI-backed pentesting gives your organization faster and more thorough insight into vulnerabilities.

Contact us