Security / Web, app & API
Website security assessment for web apps and APIs
Friday Works provides a website security assessment covering the attack surface, configuration, authentication, authorisation and important business flows within an agreed scope. Findings focus on reproducible evidence, real impact and a remediation order the engineering team can act on.
Best-fit scope
When does this service create value?
Before launch
Review important controls before a website or application receives real users and data.
After a major change
Check sign-in, authorisation, payment, upload or API flows following a significant release.
Establish a baseline
Create a prioritised risk and remediation backlog for a system that has not had a structured review.
Deliverables
What your team receives
- 01
Agreed scope, test accounts, time window and rules of engagement.
- 02
Technical review and controlled manual testing of the web app or API.
- 03
A findings report with minimal evidence, impact and remediation guidance.
- 04
An engineering walkthrough and one confirmation round within the agreed scope.
Process
From business problem to operating system
01. Define scope
List domains, user roles, important functions, sensitive data and testing limits.
02. Map the application
Understand the observable architecture, authentication, permissions and data-entry points.
03. Test carefully
Validate hypotheses with low-impact checks and preserve a baseline, negative control and reproducible evidence.
04. Report & retest
Prioritise by impact and feasibility, help the team understand the fix and verify the agreed changes.
Timeline
A roadmap shaped by scope and evidence
Corporate website
Often several working days when scope, access and environment are ready.
Web application or API
Often 1–3 weeks depending on user roles, business flows and the size of the test surface.
Confirmed scope
Set only after the assets, functions and safe operating constraints are understood.
Frequently asked questions
Before we begin
01Is this a full penetration test or Red Team engagement?
No. The current service is described as a scoped web app and API security assessment. If a requirement calls for a full penetration test or Red Team programme, capability, scope and appropriate partners must be confirmed before commitment.
02Will the assessment disrupt the system?
Testing is designed to be low impact and follows agreed rules. Actions that might alter data or affect service are not performed without an appropriate environment and explicit authorisation.
03Will the report help developers remediate issues?
Yes. Each finding includes context, minimal evidence, impact and practical remediation direction; the walkthrough lets the team ask questions before retesting.
Talk to Friday Works
Understand risk before it becomes an incident
Share the system scope, user roles and a suitable testing window. Friday Works will propose an assessment with clear safety boundaries.
Describe your project