Penetration testing
Penetration Testing for Web Apps and APIs
A penetration test is an authorised attempt to break into your own system, so you learn which attack paths are real before someone else uses them.
Introductory program
Free security audit
One full engagement at no fee, delivered to the same standard and depth as a paid one. In return we ask for one thing: recognition — permission to reference this engagement in the cyberagent.id portfolio. You may remain anonymous.
What separates a real test from scanning
- Written authorisation with explicit limits and emergency contacts on both sides.
- Real exploitation with proof of impact, not a list of outdated library versions.
- Prioritisation by business impact: what an attacker could read, change or stop.
- Re-testing so remediation does not stop at "it is patched".
Areas we test
| Area | Example attack paths attempted |
|---|---|
| Authentication | Weak credentials without throttling, non-expiring tokens, sessions alive after logout. |
| Authorisation | Reading or changing another user's data, escalating from user to admin. |
| Input | SQL injection, XSS, SSRF, malicious file upload, insecure deserialisation. |
| Business logic | Client-side pricing, reusable coupons, balances increased via negative values. |
| Infrastructure | Open services, exposed admin panels, public backups, weak TLS configuration. |
| AI systems | Prompt injection, internal data leaked through answers, unrestricted tool access. |
Rules of engagement
- Non-destructive: no data deletion, no service outages, no hidden access left behind.
- Critical findings reported as soon as they are confirmed, not held to the end of the project.
- Data seen during testing is treated as confidential.
- Written limits: what is allowed, what is not, and who can change scope.
Frequently asked questions
What is a penetration test?
An authorised attempt to break into your own system the way a real attacker would: abusing weak access controls, stealing sessions, injecting malicious input and bending business logic.
How much does it cost?
Quoted per project after a scoping call: number of applications, whether source review is included, how many user roles exist, and whether payments or AI systems are involved.
Will testing disrupt our service?
No. Testing is designed to be non-destructive, and anything risky is approved with you first.
Is written authorisation required?
Yes, without exception. We only test assets you own or are authorised in writing to test.
Related services
Start with one email to founder@cyberagent.id listing the assets you want tested. You get scoping questions and a written quote back.