M
Marco T.
OSCP · ✓ vetted
REST and GraphQL API security assessment
web
API-first testing driven from your spec and from what the service actually accepts. Heavy on authorisation, rate limiting, and object-level access control.
web
API-first testing driven from your spec and from what the service actually accepts. Heavy on authorisation, rate limiting, and object-level access control.
Up to 40 operations. Auth, authorisation, input validation.
Unlimited operations, GraphQL introspection abuse, BOLA/BFLA matrix.
Everything in Standard, plus a per-endpoint authorisation matrix and CI test suite.
Thorough on authorisation, and the per-endpoint matrix is genuinely reusable. Marked down only because delivery slipped a day.