DebugSol

Methodology

How we test, and what you get.

Every engagement follows published standards, is run by a certified tester, and ends in a plain-English report you can act on and share. AI speeds up recon and reporting; a person confirms every finding before it reaches you.

Standards

The frameworks your auditors expect.

OWASP WSTG

Web applications

The Web Security Testing Guide — the standard checklist for web app testing.

OWASP API Top 10

APIs

The common, high-impact API risks: broken object- and function-level authorisation, and more.

OWASP MASTG

Mobile apps

The Mobile Application Security Testing Guide for Android and iOS.

PTES

Network & infra

The Penetration Testing Execution Standard for external and internal network work.

NIST SP 800-115

Technical testing

The US standard for planning and conducting security assessments.

CIS Benchmarks

Cloud & M365

Consensus hardening baselines for AWS, Azure, GCP and Microsoft 365.

The engagement

Five stages, no surprises.

01

Scope

A short form fixes the price and the targets. Nothing outside it is touched.

02

Authorise

Signed scope and rules of engagement — the legal line before any test.

03

Test

Hands-on testing by a certified tester. Critical findings reach you the same day.

04

Report

Plain-English findings with fixes, mapped to your framework.

05

Retest

We re-check your fixes and issue a retest certificate.

What we check

Depth where it matters.

  1. 01Recon and mapping — every page, parameter and API endpoint, and the tech stack
  2. 02Authentication and session — login, reset, MFA, tokens, timeouts, brute-force
  3. 03Authorisation — the core SaaS test: IDOR and role boundaries, run as every role
  4. 04Input handling — injection, cross-site scripting, SSRF, XXE, file-upload abuse
  5. 05Business logic — skipping payment, replaying requests, abusing limits and coupons
  6. 06API Top 10 — object- and function-level authorisation, mass assignment, rate limits
  7. 07Configuration and exposure — cloud, headers, secrets, and anything indexed that should not be

Severity

How we rate findings.

Scored with CVSS v3.1 (or v4.0 on request), then adjusted for real business impact.

RatingCVSSWhat it meansHow you hear about it
Critical 9.0–10.0Direct takeover or mass data exposure, easy to exploitPhone call the same day
High 7.0–8.9Serious access or data exposure with some conditionsIn the next status email
Medium 4.0–6.9Needs chaining or has limited impactIn the report
Low 0.1–3.9Hardening and hygieneIn the report
Informational —Good practice, no direct riskIn the report

The deliverable

What every report contains.

Want to judge the real thing? A redacted sample report is the best way — request it and we'll send it over.

Get a fixed quote in 24 hours.

Or run a free exposure snapshot — no login, no obligation.