Identity and authorisation
We validate boundaries between users, roles and tenants.
- IDOR/BOLA and privilege escalation
- Sessions, MFA, password reset and account recovery
- OAuth/OIDC, SSO, tokens and API keys
We test the complete path from an entry point to impact on data, money and business operations — not just isolated endpoints.
Automated scanners can identify a subset of technical defects. We also test relationships between roles, tenants, functions and integrations: the places where material vulnerabilities usually emerge.
We validate boundaries between users, roles and tenants.
We model a real attacker rather than stopping at an OWASP list.
Inputs, integrations and data flows are tested in context.
We agree assets, test accounts, exclusions, work windows and the urgent channel for critical findings.
We build a model of roles, data, functions, APIs and trust boundaries before chaining weaknesses.
Impact is confirmed with the smallest safe proof. We do not retrieve data that is unnecessary for validation.
We provide executive and technical layers, review fixes with the team and verify their effectiveness.
The model demonstrates our reporting standard: confirmed impact first, followed by evidence, conditions and a specific control.
This is a reporting example, not a client engagement or a claim that a specific issue was found.
An account A request references an account B resource
The backend validates the session but not resource ownership
A minimal proof confirms access to one controlled record
The fix adds object-level authorisation and a regression test
Usually from several days to several weeks. Timing depends on roles, endpoints, integrations and access model. We quote after a short scoping call.
Yes when the scope and risk allow it. We use limits, test accounts and agreed rules. Scenarios that could disrupt service move to staging.
The report contains evidence and remediation guidance, but a technical walkthrough is standard. The team can challenge assumptions and agree a safe fix.
Send a short architecture overview, number of roles and target date. We will return with assumptions, scope and a quote.