Web Application Assessment
Evaluates the security and overall health of a web application on a recurring basis, catching regressions introduced by new releases before they reach production.

What's inside.
Vulnerability Scanning
Automated scanning for SQL injection, cross-site scripting, and cross-site request forgery.
Code Review
Analysis of source code for security issues and best practices.
Configuration Review
Evaluation of server and network configuration against best practice.
Remediation Guidance
Recommendations on how to fix identified vulnerabilities.
What the solution aims to do.
Identify security risks
Find the vulnerabilities and weaknesses in the web application that an attacker could exploit.
Improve security posture
Turn assessment results into guidance for reducing the risk of incidents and protecting sensitive data.
Compliance
Support regulatory requirements and industry standards including PCI DSS, HIPAA, and OWASP.
Enhance the development process
Surface the practices and the gaps in your software development process, not just in the running application.
Increase customer trust
Demonstrable commitment to security and privacy, which is what customers actually assess you on.
What you receive.
The exact set depends on the package selected, but a Web Application Assessment Solution typically includes the following.
Where this connects.
Web Application VA/PT
The consultant-led engagement, where findings are manually validated and exploited.
Software Source Code Review
Goes deeper into the source than automated code review does.
Vulnerability Management
The same continuous model applied across infrastructure rather than applications.
Common questions.
What does the assessment actually check?
Automated scanning for issues such as SQL injection, cross-site scripting, and cross-site request forgery, plus source code analysis and a review of server and network configuration against best practice.
Is this a one-off test?
No. It evaluates the security and overall health of a web application on a recurring basis, which is what catches regressions introduced by new releases before they reach production.
Do we get told how to fix what is found?
Yes. Remediation guidance covering how to resolve each identified vulnerability is part of the service, alongside the assessment reports detailing the risks.
Is it hosted by us or by you?
Either. The software tool can be deployed on-premises or in the cloud, supplied with a license agreement, user documentation, technical assistance, and continuous updates.