Each one below is a real body of work with a defined output. Pick the ones that match what you run — or send us the URL and we'll tell you which apply.
All of them produce the artifact a SOC 2, ISO 27001 or enterprise customer security review asks for: a dated report with a named tester, a written scope and a re-test record. We are not an auditor and we issue no certificate — we give you the evidence the auditor wants to see.
A human works through your application the way an attacker would: every input, every role boundary, every state transition. Automation sweeps first; the findings that matter come out of the manual pass.
Broken access control between users and roles, injection and XSS, authentication and session weaknesses, and business-logic abuse — discounts that stack, quantities that go negative, workflows that skip a step.
Usually a change in one layer: an ownership check moved into the data access path, escaping restored on output, a state machine that refuses illegal transitions. We name the file pattern, not just the vulnerability class.
Your API is the real application; the UI is a suggestion. We test it directly — documented routes, undocumented routes, and the ones we find in your JavaScript bundle.
Object-level authorization gaps, mass assignment, missing rate limits, verbose errors, endpoints that were never meant to ship, and versioned routes that were deprecated in the docs but never switched off.
Authorization asserted per object rather than per route, explicit allow-lists on writable fields, and a rate-limit policy applied at the gateway so new endpoints inherit it by default.
Everything the internet can see that belongs to you: hosts, subdomains, ports, certificates, cloud buckets, third-party embeds, exposed dashboards, and the things a previous developer left running.
Forgotten staging environments with production data, subdomains pointing at deprovisioned services and open to takeover, admin panels on non-standard ports, and credentials in public repositories or client bundles.
A prioritized decommission list, DNS records to remove, and access controls to put in front of what has to stay. Most of this work is deletion, which is the cheapest security you can buy.
A review of the settings around your application: TLS, security headers, cookie flags, CORS, storage permissions, email authentication and the defaults your platform shipped with.
Missing or permissive CSP and CORS, cookies without Secure or SameSite, over-broad bucket policies, SPF and DMARC that let anyone send mail as your domain, and debug settings alive in production.
A list of specific settings with the exact values to set, ordered by how much risk each one removes per minute of work. Most teams close this list in an afternoon.
Scope an engagement See what it costs Earthshaker SecurityWe find the cracks before they do. Automated and human-verified security testing for web applications.
earthshakersecurity.com · contact@earthshakersecurity.com
Earthshaker Security