Skip the film

02 / Stack layer

Penetration testing, instrumented and signed.

A penetration test is an authorized, simulated attack by security specialists that proves which vulnerabilities are actually exploitable, followed by a report with evidence, risk ratings and concrete fixes.

Our penetration testing services cover web apps, APIs and cloud. Our own instruments do the recon, replay and triage; a tester does the thinking.

30-minute scoping call, no obligation.

  • WEB APP
  • API GATEWAY
  • IDENTITY
  • TENANT DATA
  • OBJECT STORAGE
  • CLOUD ACCOUNT
  1. 01 WSTG-BUSLBUSINESS LOGIC
  2. 02 API1:2023BROKEN OBJECT LEVEL
    AUTHORIZATION
    GET /claims/48213 / 200
  3. 03 WSTG-ATHZAUTHORIZATION
  4. 04 API3:2023PROPERTY LEVEL
    AUTHORIZATION
  5. 05 EXPOSED STORAGE
  6. 06 IDENTITY AND ACCESS
FIG. 1 / THE SECTION. The stack half of the plate as an exploded tower, from the web app down to the cloud account. A section plane descends through it like an architect’s cut: each layer it passes shows its cut face and one line inside, where a tester looks.

What the film shows

  1. 01 / WEB APP: WSTG-BUSL / BUSINESS LOGIC.
  2. 02 / API GATEWAY: API1:2023 / BROKEN OBJECT LEVEL AUTHORIZATION.
  3. 03 / IDENTITY: WSTG-ATHZ / AUTHORIZATION.
  4. 04 / TENANT DATA: API3:2023 / PROPERTY LEVEL AUTHORIZATION.
  5. 05 / OBJECT STORAGE: EXPOSED STORAGE.
  6. 06 / CLOUD ACCOUNT: IDENTITY AND ACCESS.

THE STACK LAYER

A pentest is time-boxed. Attackers are not. So we spend the box on thinking.

A web application or API test in the Netherlands typically costs EUR 5,000 to 15,000, which at our rates buys four to ten tester days. Scanners cover the known patterns in minutes, so those days should go where scanners cannot follow: authorization between users and tenants, business logic, and the chains of small issues that add up to one real risk.1

COVERAGE

What each package tests, by framework.

Every category is one row in our test plan. The scoping call moves categories in or out; the report says which ran.

What each package tests, by framework.
FrameworkWEB & APICLOUD & INFRA
OWASP WSTG categories12 categories / ids WSTG-INFO to WSTG-APIT12 of 12 in the package
  • INFO: Information exposure and application mapping. In the package.
  • CONF: Configuration and deployment management. In the package.
  • IDNT: Identity management: roles, registration and provisioning. In the package.
  • ATHN: Authentication: credentials, recovery and lockout. In the package.
  • ATHZ: Authorization and tenant isolation. In the package.
  • SESS: Session management: tokens, cookies, logout and timeout. In the package.
  • INPV: Input validation and injection handling. In the package.
  • ERRH: Error handling without information leakage. In the package.
  • CRYP: Transport security and cryptographic choices. In the package.
  • BUSL: Business logic and multi-step workflow integrity. In the package.
  • CLNT: Client-side security: DOM, cross-origin policy and framing. In the package.
  • APIT: GraphQL and API surface review. In the package.
1 of 12 in the package
  • INFO: Information exposure and application mapping. Not in this package.
  • CONF: Configuration and deployment management. In the package.
  • IDNT: Identity management: roles, registration and provisioning. Not in this package.
  • ATHN: Authentication: credentials, recovery and lockout. Not in this package.
  • ATHZ: Authorization and tenant isolation. Not in this package.
  • SESS: Session management: tokens, cookies, logout and timeout. Not in this package.
  • INPV: Input validation and injection handling. Not in this package.
  • ERRH: Error handling without information leakage. Not in this package.
  • CRYP: Transport security and cryptographic choices. When the system has it: object storage, containers, serverless, hosted AI.
  • BUSL: Business logic and multi-step workflow integrity. Not in this package.
  • CLNT: Client-side security: DOM, cross-origin policy and framing. Not in this package.
  • APIT: GraphQL and API surface review. Not in this package.
OWASP API Security Top 10 (2023)10 categories / ids API1:2023 to API10:202310 of 10 in the package
  • API1: Object level authorization on every endpoint. In the package.
  • API2: API authentication and token handling. In the package.
  • API3: Property level authorization on reads and writes. In the package.
  • API4: Rate limits and resource consumption controls. In the package.
  • API5: Function level authorization for roles and admin routes. In the package.
  • API6: Protection of sensitive business flows. In the package.
  • API7: Server side request forgery defenses. In the package.
  • API8: API security configuration and hardening. In the package.
  • API9: API inventory, versions and undocumented endpoints. In the package.
  • API10: Safe consumption of third-party APIs. In the package.
1 of 10 in the package
  • API1: Object level authorization on every endpoint. Not in this package.
  • API2: API authentication and token handling. Not in this package.
  • API3: Property level authorization on reads and writes. Not in this package.
  • API4: Rate limits and resource consumption controls. Not in this package.
  • API5: Function level authorization for roles and admin routes. Not in this package.
  • API6: Protection of sensitive business flows. Not in this package.
  • API7: Server side request forgery defenses. When the system has it: object storage, containers, serverless, hosted AI.
  • API8: API security configuration and hardening. In the package.
  • API9: API inventory, versions and undocumented endpoints. Not in this package.
  • API10: Safe consumption of third-party APIs. Not in this package.
Cloud and infrastructure12 categories0 of 12 in the package
  • IAM: Least privilege for users, roles and service accounts. Not in this package.
  • TRUST: Privilege escalation paths and cross-account trust. Not in this package.
  • SIGN-IN: Sign-in hardening: federation, MFA and conditional access. Not in this package.
  • STORAGE: Object storage exposure and access policies. When the system has it: object storage, containers, serverless, hosted AI.
  • SECRETS: Secrets in code, images and secret stores. When the system has it: object storage, containers, serverless, hosted AI.
  • CI/CD: CI/CD pipeline integrity and build permissions. Not in this package.
  • METADATA: Instance metadata and workload identity protection. Not in this package.
  • CONTAINERS: Container and Kubernetes configuration. Not in this package.
  • SERVERLESS: Serverless functions and event triggers. Not in this package.
  • AI SERVICES: Hosted AI services: model endpoints, keys and quotas. Not in this package.
  • LOGGING: Logging and audit trail coverage. Not in this package.
  • EXTERNAL: External infrastructure: exposed hosts, services and remote access. Not in this package.
9 of 12 in the package
  • IAM: Least privilege for users, roles and service accounts. In the package.
  • TRUST: Privilege escalation paths and cross-account trust. In the package.
  • SIGN-IN: Sign-in hardening: federation, MFA and conditional access. In the package.
  • STORAGE: Object storage exposure and access policies. In the package.
  • SECRETS: Secrets in code, images and secret stores. In the package.
  • CI/CD: CI/CD pipeline integrity and build permissions. In the package.
  • METADATA: Instance metadata and workload identity protection. In the package.
  • CONTAINERS: Container and Kubernetes configuration. When the system has it: object storage, containers, serverless, hosted AI.
  • SERVERLESS: Serverless functions and event triggers. When the system has it: object storage, containers, serverless, hosted AI.
  • AI SERVICES: Hosted AI services: model endpoints, keys and quotas. When the system has it: object storage, containers, serverless, hosted AI.
  • LOGGING: Logging and audit trail coverage. In the package.
  • EXTERNAL: External infrastructure: exposed hosts, services and remote access. In the package.
  • In the package
  • When the system has it: object storage, containers, serverless, hosted AI
  • Not in this package

Mapped to OWASP Web Security Testing Guide 4.2 and OWASP API Security Top 10 2023; the cloud and infrastructure categories follow our own test catalogue.

All 34 categories in plain words
INFO
WSTG-INFO Information Gathering: Information exposure and application mapping.
CONF
WSTG-CONF Configuration and Deployment Management Testing: Configuration and deployment management.
IDNT
WSTG-IDNT Identity Management Testing: Identity management: roles, registration and provisioning.
ATHN
WSTG-ATHN Authentication Testing: Authentication: credentials, recovery and lockout.
ATHZ
WSTG-ATHZ Authorization Testing: Authorization and tenant isolation.
SESS
WSTG-SESS Session Management Testing: Session management: tokens, cookies, logout and timeout.
INPV
WSTG-INPV Input Validation Testing: Input validation and injection handling.
ERRH
WSTG-ERRH Testing for Error Handling: Error handling without information leakage.
CRYP
WSTG-CRYP Testing for Weak Cryptography: Transport security and cryptographic choices.
BUSL
WSTG-BUSL Business Logic Testing: Business logic and multi-step workflow integrity.
CLNT
WSTG-CLNT Client-side Testing: Client-side security: DOM, cross-origin policy and framing.
APIT
WSTG-APIT API Testing: GraphQL and API surface review.
API1
API1:2023 Broken Object Level Authorization: Object level authorization on every endpoint.
API2
API2:2023 Broken Authentication: API authentication and token handling.
API3
API3:2023 Broken Object Property Level Authorization: Property level authorization on reads and writes.
API4
API4:2023 Unrestricted Resource Consumption: Rate limits and resource consumption controls.
API5
API5:2023 Broken Function Level Authorization: Function level authorization for roles and admin routes.
API6
API6:2023 Unrestricted Access to Sensitive Business Flows: Protection of sensitive business flows.
API7
API7:2023 Server Side Request Forgery: Server side request forgery defenses.
API8
API8:2023 Security Misconfiguration: API security configuration and hardening.
API9
API9:2023 Improper Inventory Management: API inventory, versions and undocumented endpoints.
API10
API10:2023 Unsafe Consumption of APIs: Safe consumption of third-party APIs.
IAM
Least privilege for users, roles and service accounts.
TRUST
Privilege escalation paths and cross-account trust.
SIGN-IN
Sign-in hardening: federation, MFA and conditional access.
STORAGE
Object storage exposure and access policies.
SECRETS
Secrets in code, images and secret stores.
CI/CD
CI/CD pipeline integrity and build permissions.
METADATA
Instance metadata and workload identity protection.
CONTAINERS
Container and Kubernetes configuration.
SERVERLESS
Serverless functions and event triggers.
AI SERVICES
Hosted AI services: model endpoints, keys and quotas.
LOGGING
Logging and audit trail coverage.
EXTERNAL
External infrastructure: exposed hosts, services and remote access.

HOW WE TEST

Your budget buys thinking time, not scanning time.

Our instruments take the work a machine does well, at machine pace. The tester keeps every decision about what to test, what it means and what goes in your report. Severity is rated in CVSS v4.0, and every stack finding comes with the exact requests that reproduce it. Read the method.2

Our instruments doThe tester does
Asset discovery and recon correlationThe threat model: what an attacker would want from you
Crawling, traffic capture and replayDecides what deserves hours and what does not
Test cases at volumeBusiness logic, authorization models and multi-step abuse
Response triage and deduplicationConnects small issues into one real risk
First-draft report formattingSeverity, fix guidance and every word you read
Replaying every finding at retestConfirms the fix closes the cause, not the symptom
FIG. 2 / INSTRUMENTS AND PERSON. What our tooling does at machine pace, and what the tester decides.

ENGAGEMENT

From the first call to the retest.

The same eight steps for every test, AI or stack. Dates go in the rules of engagement before anything starts.

  1. 01

    SCOPING CALL

    30 minutes on what you ship, what matters and what stays out of scope.

  2. 02

    FIXED QUOTE

    One price for the agreed scope, after the call.

  3. 03

    RULES OF ENGAGEMENT

    Written authorization, test windows, named contacts on both sides and how to stop the test. Read the rules.

  4. 04

    TEST WINDOW

    4 to 10 testing days, fixed on the call.

  5. 05

    CRITICAL FINDINGS

    Reported to your named contact before the report.

  6. 06

    REPORT

    Findings with evidence, severity and fixes, and a one-page letter you can share.

  7. 07

    RETEST

    We replay every finding after you fix it and update the report.

PACKAGES

Two packages, priced in the open.

The web app and its API first, because that is where users meet. Every range covers the testing days, the report and the letter.

WEB & API

Web & API

Web applications and the REST or GraphQL APIs behind them.

COVERS

  • Authorization and tenant isolation, role by role
  • Business logic and multi-step workflows
  • Authentication, sessions and tokens
  • Object, property and function level access in the API
EUR, EXCL. VAT
EUR 5,000 to 15,000
TESTING DAYS
4 to 10

Web application penetration testingAPI penetration testing

CLOUD & INFRA

Cloud & Infrastructure

AWS, Azure or GCP accounts and the hosts you expose.

COVERS

  • Identity and access: roles, trust and escalation paths
  • Exposed storage and secrets in build pipelines
  • Workloads: containers, serverless and metadata
  • External hosts, services and remote access
PRICE
Quoted per scope
TESTING DAYS
Scoped per account

Cloud penetration testing

Why a human-led test costs more than an automated one.

Automated tests sell from about EUR 1,250 to 3,500 and are good at the known patterns. A human-led test spends its days on business logic, on what one user can do to another, and on the chains of small issues that add up to one real risk: the findings an automated run cannot reason its way to.3

Pricing for every package

SAMPLE FINDING

What one finding looks like in your report.

Finding F-01 of our sample report, word for word: a fictional insurer, the real format. Summary level only, with the fix.

F-01CRITICALCVSS-B 9.3API1:2023STACK LAYER

The claims API serves any tenant’s claim to the assistant’s token

BUSINESS IMPACT
Anyone who can steer the assistant can read and change another customer’s claim.
EVIDENCE
REQUESTS REQ-07 TO REQ-11, APPENDIX B The requests that reproduce it, with both test accounts named.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N4
FIX
Check authorization on every object, not only at login: scope the assistant’s token to one tenant and enforce claim ownership in the API.
RETEST
FIXED 2026-09-24 Ownership is now enforced per claim; all five requests are refused.
SAMPLE / FICTIONAL CLIENT / REAL FORMAT

FROM THE READING ROOM

Three guides for buying a pentest well.

Questions about penetration testing.

Which penetration testing services do you offer?

Web application, API and cloud penetration tests, sold as Stack Pentest in two packages: Web and API, and Cloud and Infrastructure. If your product ships an AI feature on top, Launch Clearance tests the feature and the platform under it in one scope, with one report that also covers the paths between them.

Black box or grey box: which do we need?

Grey box, in most cases. With test accounts in two tenants and your API documentation, a tester spends the days on authorization and business logic instead of guessing at the surface. Black box shows what an outsider can find unaided, which suits a review of your external attack surface. We advise per scope on the call.

Do you use automated tools?

Yes. Our own instruments handle recon, traffic replay, response triage and the first draft of the report. A person decides what to test, works through the business logic and judges every finding. The tooling gives the tester more hours for the parts that need thinking; it never decides what goes into your report.

How do you handle our data and credentials?

You share credentials through a channel agreed in the rules of engagement, never by email or chat, and we prefer dedicated test accounts you can switch off afterwards. The rules of engagement also record which systems, accounts and data are in scope, who may access them on our side, and how long anything we receive is kept.

How long does a penetration test take?

Usually 4 to 10 testing days for a web application and its API, depending on the number of roles, tenants and integrations. Cloud and infrastructure tests are scoped per account. The scoping call fixes the number of days before you receive a quote, and the report follows the last test day with every finding and its fix.

What do we need to prepare?

A scope list, two test accounts per role in two separate tenants, API documentation if you have it, and a signed authorization naming the systems and the test window. Tell your hosting provider and any security monitoring team about the window, and name a contact who can stop the test at any time.

03 / Clearance

Shipping AI on a SaaS platform? Test both layers at once.

Launch Clearance is one scope for the feature and the platform under it, including the issues that only show up when both layers are tested together.

SAAS + AI FEATURE

EUR 10,000 to 20,000

30-minute scoping call, no obligation.