Web app & API penetration testing

Security testing your customers will actually accept.

A senior human tester attacks your application the way a real attacker would — then explains what they found in plain English. Fixed quote up front. Report written for the people who asked you for it.

Built for teams who've been asked for a pentest

Most of our clients aren't security experts — they've been asked for proof of testing and want it handled properly, without the enterprise price tag.

A customer is asking

An enterprise prospect sent a security questionnaire, or procurement wants a recent pentest report before they'll sign. We test, you send the report, the deal moves.

An auditor is asking

SOC 2, ISO 27001 or PCI DSS requires independent testing. You get a report an auditor will recognise, plus a retest letter showing the fixes landed.

A regulator is asking

DORA puts annual security testing on Irish financial firms — payments, funds, brokers, credit unions. We scope it to what the regulation actually asks of you.

What we test

Web applications and the APIs behind them — the things your business actually runs on.

  • Authentication & session handling — login, MFA, password reset, session fixation
  • Access control — can user A read user B's data? Can a standard user act as an admin?
  • Business logic — the flaws scanners can't find: broken workflows, skipped steps, abused discounts
  • APIs — REST and GraphQL: object-level authorisation, mass assignment, rate limits
  • Injection & classic flaws — SQLi, XSS, SSRF and the rest of the OWASP Top 10
  • Attack chaining — how small issues combine into an account takeover or data breach

How it works

From first contact to final report, without jargon or drama.

01

Tell us about your app

Five minutes on the quote form. We come back within one business day with a fixed price and a proposed scope — no calls required unless you want one.

02

We sign, then we test

NDA and testing authorisation first, always. Then a senior tester spends dedicated days attacking your app with test accounts, the way a real attacker with a login would.

03

Report, fix, retest

A plain-English report: what we found, what it means for your business, and exactly how to fix it. Once you've fixed, we retest and issue a letter confirming it.

Why pentests.ie

  • Humans find what matters. Automation handles the routine checks; certified senior testers (OSCP-level and above) do the manual work that finds real breaches.
  • Fixed quotes, no surprises. You know the price before you commit. The retest is part of the job, not an upsell.
  • EU-based, GDPR-native. Testers inside the EU, data processing agreement as standard, all testing evidence deleted after the engagement.
  • Founded by a solicitor. Our founder runs an Irish law firm. Confidentiality, authorisation letters and watertight paperwork aren't an afterthought — they're the day job.
  • We test our own software first. Our methodology was built attacking our own production-grade case-management system — not a slide deck.
  • Reports people can read. Executive summary for the board, technical detail for the devs, evidence for the auditor.

Questions people ask

How much does a penetration test cost?

It depends on the size of the application — mainly how many user roles and how much functionality there is. Tell us about your app and you'll have a fixed, all-in quote within one business day. The quote is free and doesn't commit you to anything.

Is this safe to run against our application?

Testing only starts after you've signed a written authorisation defining exactly what's in scope — that protects both of us, and it's required under Irish law. We prefer testing a staging environment; if only production exists, we agree rules of engagement (no destructive testing, agreed hours, an emergency stop contact).

What do we need to give you?

A URL and test accounts for each user role — we'll tell you exactly what to set up. You don't need to prepare documentation or sit on calls. Most clients spend under an hour on their side of the whole engagement.

How long does it take?

Typically two to three weeks from booking to report, with the testing itself taking a number of dedicated days depending on scope. If a customer deal is waiting on the report, tell us the deadline and we'll be straight with you about whether we can hit it.

Will the report satisfy our customer / auditor / regulator?

The report is written for exactly that audience: methodology, scope, findings with severity ratings, remediation guidance, and a retest letter once fixes are verified. It's the format security questionnaires and SOC 2 / ISO 27001 auditors expect to see.

What happens to our data afterwards?

We work under NDA and a data processing agreement. Testing evidence is held securely during the engagement and deleted once the retest closes, and we confirm that deletion in writing. Testers are EU-based, so your data doesn't leave the EU.

Get a fixed quote this week

Five minutes of your time. One business day to a price. No sales calls unless you ask.

Get a quote