Some of our clients we can name. Most we cannot — penetration testing is done under NDA, and the organisations that most need it are the least able to say so publicly. Where we cannot give you a name, we give you the role and the sector instead, rather than a name we cannot evidence.
In the many years I have been working with AppSec Labs they have constantly provided high quality service, fair pricing, and peace of mind that my application security needs are in the best hands. Many companies today “claim” to be security experts but once you go beyond the basics, their limitations become clear. AppSec Labs is unique in that they can address 100% of our security needs end-to-end. Web application, mobile app, embedded firmware, wireless — they have genuine 360 expertise.
AppSec-Labs is always there for me when application security is a need.
They found an authorization bypass in our merchant portal that could have exposed transaction data for thousands of businesses. No scanner would have caught that — it required understanding our business logic.
They found a critical IDOR in our claims portal within the first two days. We had been live for 18 months without anyone catching it.
Their API security assessment covered edge cases we hadn’t thought of — broken object-level authorization, mass assignment, rate limiting gaps. The report read like a masterclass in API security.
We integrate with 200+ third-party APIs. AppSec Labs tested not just our code but how we handle upstream failures, malicious responses and credential rotation. That holistic view is rare.
We process 50 million API calls per day. Their team tested our rate limiting, authentication and data validation at scale — not just with Burp Suite, but with custom scripts that simulated real attack patterns.
Our clinical trial management system holds patient data subject to FDA 21 CFR Part 11. AppSec Labs understood the regulatory context and focused their testing on the areas that matter most for compliance.
We needed SOC 2 compliance fast. AppSec Labs didn’t just run the pentest — they helped us understand which findings were blockers and which could wait, so we passed the audit on our first attempt.
Our regulators required an independent penetration test. AppSec Labs delivered a report so detailed and well-structured that our compliance team uses it as a reference for every audit since.
Every quote on this page comes from a real engagement. The two at the top are named with their permission; the rest are anonymised because our agreement with those clients requires it — not because there is anything vague about the work.
Want to know what we would find in your application? Talk to us — or read what 700 penetration tests actually find.
