VVeyraSecurity
Services · application-security-assessment

Application Security Assessment.

Gray-box assessment of a web application's authentication, authorization, business logic, and data handling. Manual validation with tool-assisted discovery.

§ 01 — Scope

What it covers.

  • Item 01

    Authentication, session management, and account-recovery flows.

  • Item 02

    Authorization across every documented role, including horizontal and vertical escalation paths.

  • Item 03

    Business-logic flaws specific to the application domain.

  • Item 04

    Data handling, including unintended exposure of personal data and credentials.

  • Item 05

    Common web vulnerabilities (XSS, CSRF, SSRF, deserialization) where applicable.

§ 02 — Inputs

What we need from you.

  • Item 01

    Per-role test credentials and documentation of role boundaries.

  • Item 02

    A walkthrough of high-value business workflows.

  • Item 03

    Architecture context: hosting, identity provider, third-party integrations.

  • Item 04

    Authorization to test before any traffic is sent.

§ 03 — Operating method

How it runs.

  • Item 01

    Pre-engagement intake captures scope, environments, and emergency-stop rules.

  • Item 02

    Mutual non-disclosure agreement is signed before any sensitive scope crosses.

  • Item 03

    Statement of Work, Authorization to Test, and Rules of Engagement are countersigned.

  • Item 04

    Active testing runs against the agreed environment.

  • Item 05

    Findings are validated manually before any severity is assigned.

  • Item 06

    Report is reviewed against a defensibility checklist before delivery.

§ 04 — Deliverable

What the deliverable is.

  • Item 01

    Executive summary describing scope, methodology, and the disposition of findings.

  • Item 02

    Per-finding write-up with reproduction, evidence, severity, and remediation guidance.

  • Item 03

    Evidence pack referencing the assessed application state at testing time.

§ 05 — Defensibility

What Veyra will not claim.

  • Item 01

    We will not say the application is secure.

  • Item 02

    We will not include findings without reproducible evidence.

  • Item 03

    We will not imply accreditation we do not hold.

Next step

Read a redacted sample report, or describe the system you want assessed.

Engagement requests receive a reply from a named assessor within one business day.