Security / Web, app & API

Website security assessment for web apps and APIs

Friday Works provides a website security assessment covering the attack surface, configuration, authentication, authorisation and important business flows within an agreed scope. Findings focus on reproducible evidence, real impact and a remediation order the engineering team can act on.

Best-fit scope

When does this service create value?

01

Before launch

Review important controls before a website or application receives real users and data.

02

After a major change

Check sign-in, authorisation, payment, upload or API flows following a significant release.

03

Establish a baseline

Create a prioritised risk and remediation backlog for a system that has not had a structured review.

Deliverables

What your team receives

  1. 01

    Agreed scope, test accounts, time window and rules of engagement.

  2. 02

    Technical review and controlled manual testing of the web app or API.

  3. 03

    A findings report with minimal evidence, impact and remediation guidance.

  4. 04

    An engineering walkthrough and one confirmation round within the agreed scope.

Process

From business problem to operating system

01. Define scope

List domains, user roles, important functions, sensitive data and testing limits.

02. Map the application

Understand the observable architecture, authentication, permissions and data-entry points.

03. Test carefully

Validate hypotheses with low-impact checks and preserve a baseline, negative control and reproducible evidence.

04. Report & retest

Prioritise by impact and feasibility, help the team understand the fix and verify the agreed changes.

Timeline

A roadmap shaped by scope and evidence

Corporate website

Often several working days when scope, access and environment are ready.

Web application or API

Often 1–3 weeks depending on user roles, business flows and the size of the test surface.

Confirmed scope

Set only after the assets, functions and safe operating constraints are understood.

Frequently asked questions

Before we begin

01Is this a full penetration test or Red Team engagement?

No. The current service is described as a scoped web app and API security assessment. If a requirement calls for a full penetration test or Red Team programme, capability, scope and appropriate partners must be confirmed before commitment.

02Will the assessment disrupt the system?

Testing is designed to be low impact and follows agreed rules. Actions that might alter data or affect service are not performed without an appropriate environment and explicit authorisation.

03Will the report help developers remediate issues?

Yes. Each finding includes context, minimal evidence, impact and practical remediation direction; the walkthrough lets the team ask questions before retesting.

Talk to Friday Works

Understand risk before it becomes an incident

Share the system scope, user roles and a suitable testing window. Friday Works will propose an assessment with clear safety boundaries.

Describe your project