Application Security Testing

Independent, developer-focussed penetration testing for web, API and cloud security

Clear, reproducible findings — with command-line examples your engineers can act on immediately. No sales pressure, no vendor ties, just direct access to the person who did the testing.

20+ years testing experience
GIAC GWAPT certification badgeGIAC GWAPT certified
GIAC Advisory Board badgeGIAC Advisory Board Member
Findings mapped to OWASP ASVS & API Top 10
Trusted by Fintech, Healthtech & Government clients

What I test

Three areas where coding flaws, misconfigurations and vulnerable dependencies most often cause business-impacting breaches.

Web application security illustration
Web

Bring clarity to your risks

From traditional server-side templating to the latest JavaScript frameworks, across B2C, B2B and SaaS in any sector. Bring clarity to these risks to help you prioritise, mitigate and inoculate.

I also test LLM integrations — prompt injection, insecure tool use, data leakage and the application logic around AI features.

API security illustration
API

Surface common security flaws

Whether an API-only business or API-driven architecture behind a browser, mobile or desktop app — SOAP, REST, GraphQL, JSON or gRPC. Bugs reported with full detail and command-line examples so developers can reproduce and fix fast.

Cloud security illustration
Cloud

Is your data exposed?

Make sure your cloud environment protects customer data from criminal abuse or privacy breaches — insecure storage, loose access control lists, weak authentication.

01

Scope

A short call to agree targets, depth and timing — test or production, your call.

02

Test

Manual-led testing with daily feedback, so your team can start fixing before the report lands.

03

Report

Findings mapped to OWASP ASVS / API Top 10, with reproduction steps and command-line examples.

04

Retest

Confirm fixes and close the loop — direct with the person who found the issue.

“It was a very smooth process for us and the daily feedback was fantastic and meant we were working on some of the issues in development while you completed the rest of your tests.” CTO — Cyber Security
Read more client feedback →

Independent since 2012

I started security testing in the 1990s and spent the 2000s leading teams at blue-chip companies and boutique consultancies. Mothax stays staunchly independent, with no affiliation to trade bodies or ties to vendors — and no sales pressure, ever.

More about Mothax →