Application Security Assessment.
Gray-box assessment of a web application's authentication, authorization, business logic, and data handling. Manual validation with tool-assisted discovery.
What it covers.
- Item 01
Authentication, session management, and account-recovery flows.
- Item 02
Authorization across every documented role, including horizontal and vertical escalation paths.
- Item 03
Business-logic flaws specific to the application domain.
- Item 04
Data handling, including unintended exposure of personal data and credentials.
- Item 05
Common web vulnerabilities (XSS, CSRF, SSRF, deserialization) where applicable.
What we need from you.
- Item 01
Per-role test credentials and documentation of role boundaries.
- Item 02
A walkthrough of high-value business workflows.
- Item 03
Architecture context: hosting, identity provider, third-party integrations.
- Item 04
Authorization to test before any traffic is sent.
How it runs.
- Item 01
Pre-engagement intake captures scope, environments, and emergency-stop rules.
- Item 02
Mutual non-disclosure agreement is signed before any sensitive scope crosses.
- Item 03
Statement of Work, Authorization to Test, and Rules of Engagement are countersigned.
- Item 04
Active testing runs against the agreed environment.
- Item 05
Findings are validated manually before any severity is assigned.
- Item 06
Report is reviewed against a defensibility checklist before delivery.
What the deliverable is.
- Item 01
Executive summary describing scope, methodology, and the disposition of findings.
- Item 02
Per-finding write-up with reproduction, evidence, severity, and remediation guidance.
- Item 03
Evidence pack referencing the assessed application state at testing time.
What Veyra will not claim.
- Item 01
We will not say the application is secure.
- Item 02
We will not include findings without reproducible evidence.
- Item 03
We will not imply accreditation we do not hold.
Read a redacted sample report, or describe the system you want assessed.
Engagement requests receive a reply from a named assessor within one business day.