Security Services

Application Penetration Testing

Find the weaknesses in your web, mobile and API apps before
someone else does. We test the way a real attacker would, then hand you clear fixes your team can act on.

Our penetration testing is backed by CEH certification and a specialised degree in cyber security

free scoping call authorised testing only
Application penetration testing by Alke Software
What We Test

Penetration Testing and Security Testing Services

Web application penetration testing
for the apps your business runs on
Network penetration testing
internal and external, from the outside in
Vulnerability assessment
a broad sweep for known weaknesses
Secure code review
reading through the code for flaws by hand
A clear report
with every finding and how to fix it
Penetration testing report shown on a tablet
Penetration Testing Done Properly

A Security Test Run the Right Way

A good penetration test isn't a quick scan. We start by agreeing the scope with you in writing, then test your apps by hand the way an attacker would, and finish by retesting once you've patched. You see exactly what we found and what to do about it.

  • Agree the Scope Before Anything Starts
  • Hands On Testing by Real People
  • Retest Once You've Fixed Things
Tell Me More
Why Test With a Specialist

The Advantages of Testing With a Specialist

An automated scanner flags the obvious stuff and misses the rest. A tester who knows how apps break will chain small issues into a real problem, sort the noise from the risk, and tell you plainly what matters most. That's the difference between a tick box and a test you can trust.

We run tools where they help, but the real work is done by hand. A tester probes your app the way an attacker would, follows the leads a scanner can't, and confirms each finding so you're not left chasing false alarms.

Every finding is ranked by risk and written in plain language, with the steps to reproduce it and a clear fix. Your developers get something they can work from straight away, not a wall of jargon that needs a translator.

A test is only worth it if the holes get closed. Once your team has patched, we go back and check each fix actually worked and didn't open something new. You finish with proof the issues are gone, not just a list of them.
Tell Me More
Authorised Red Team Engagements

Red Team Testing, Always With Written Permission

When you want to see how your defences hold up against a determined attacker, we run red team engagements. We only ever do this with your written permission and an agreed scope, against your own systems or ours. No signed authorisation, no testing. That's the rule we work by.

  • Signed authorisation before any work begins
  • A clear scope that stays inside the lines
  • Only your own systems or ones you authorise
  • Ethical, careful work from start to finish
Talk to Us
What We Test Against

We Test Against the Weaknesses That Matter

We cover the OWASP Top 10 and the common web, API, mobile and cloud weaknesses attackers actually use, then hand you remediation advice your developers can act on.

Questions People Ask Us

Penetration Testing FAQ

Yes, always, and in writing. Before we touch anything we agree the scope with you and get signed authorisation covering exactly what we're allowed to test. We only test systems you own or are entitled to have tested. No paperwork, no testing. It keeps everyone on the right side of the law and makes sure we're looking at the right things.

A report you can actually use. It covers:
  • Every finding ranked by risk, from critical down to low
  • Plain language steps to reproduce each issue
  • A clear fix for each one your developers can follow
  • A short summary for the people who sign off on budgets
  • The scope we agreed and what we covered
  • Evidence so nothing is taken on trust
  • A sense of what to tackle first
  • A walkthrough call if you want one

It depends on the size of the app and how much of it is in scope. A single web application is often a week or so of testing, while a larger platform with several apps and APIs takes longer. We'll give you a realistic timeframe once we've scoped it with you, and we won't pad it out to fill a quote.

We work hard to keep disruption to nothing. Where we can, we test against a staging copy that mirrors production. If we do need to test live, we agree the hours with you, steer clear of anything destructive, and stay in contact so we can pause the moment you need us to. You'll always know when testing is happening.

Yes, and we think it's an important part of the job. Once your team has worked through the fixes, we go back and check each one actually closed the issue and didn't introduce anything new. You end up with written confirmation the problems are resolved, which is handy for clients, auditors or your own records.

Web applications, APIs, mobile apps on iOS and Android, and the cloud and infrastructure they sit on. We can test as an anonymous visitor or with logins for each role, so we see what a normal user, an admin and an outsider can each reach. If you're not sure what should be in scope, we'll help you work it out.

We work to recognised methods like the OWASP Top 10 and the OWASP testing guides, and we go beyond the checklist to probe the logic specific to your app. The standards make sure we don't miss the common weaknesses. The hands on testing is what catches the ones that only show up in your particular setup.

A good rule is at least once a year, and again after any big change, like a major release, a new payment flow, or moving to a new hosting setup. Code changes all the time, and a test is a snapshot of one moment. Testing on a regular basis keeps you across new weaknesses before they turn into a real problem.