What a focused test covers
- Authentication and session handling
- Authorisation: can user A reach user B’s data (broken access control)?
- Injection and input validation
- Exposed secrets and misconfigured cloud storage or databases
- API security and rate limiting
- Business-logic abuse (coupon stacking, race conditions)
- Dependencies with known vulnerabilities
Why AI-built apps need it more
AI coding tools optimise for working features. They often generate permissive database rules, hard-coded keys and API routes that trust the client. These issues are easy to fix once found, and expensive after a breach. See our vibe-coding production checklist.
Scope and cost
| Scope | Typical effort | At $100/h |
|---|---|---|
| Basic vulnerability scan and review | about 12 h | about $1,200 |
| Standard penetration test (web app + API) | about 32 h | about $3,200 |
| Deep test (multi-role, payments, complex APIs) | about 70 h | about $7,000 |
Planning figures only. High-risk or regulated systems may need specialist consultants at higher rates.
What you receive
- Executive summary and risk ratings
- Reproduction steps for each finding
- Fix guidance
- A free retest of fixed items within an agreed window (confirm in your scope)
Example findings in AI-built apps
| Finding | Why it happens | Fix |
|---|---|---|
| Any logged-in user can read any user’s records by changing an ID | Authorisation checked only in the UI | Server-side ownership checks on every query |
| API key visible in browser bundle | Key placed in front-end environment variables | Move calls to a server route; rotate the key |
| Database readable without login | Row-level security off or policy too broad | Enable and test policies as anonymous and normal users |
| Unlimited requests to an AI endpoint | No rate limit or spend cap | Per-user rate limits and provider budget alerts |
| Admin page reachable by URL | Hidden menu mistaken for access control | Role checks on admin routes and APIs |
Responsible testing rules
- Test only systems you own or have written permission to test.
- Agree scope, dates and contacts in writing.
- Use staging with test data where possible.
- Report findings privately and retest after fixes.
Book a security test From $100/h
We scope a focused test for your app and give a prioritised fix list.
Frequently asked questions
Is a pen test the same as a vulnerability scan?
No. Scans find known issues automatically; a pen test adds human reasoning to chain weaknesses and abuse business logic.
How often should we test?
Before launch, after major changes, and at least yearly for apps handling sensitive data.
Get a free quote in 24 hours
Tell us what you need. We reply with scope, timeline and a fixed price.