Home / About
Application security since 2010
About AppSec Labs
AppSec Labs is an Israeli application security company. We test web applications, REST APIs and mobile apps for organisations that cannot afford to find out the hard way — and that is the whole of our business.
Founded in 2010 by Erez Metula — author of Managed Code Rootkits (Syngress) and for five years the instructor of Black Hat's Android application hacking course — AppSec Labs has spent fifteen years doing one thing properly.
Who we are
Specialists, not generalists
What we do
Deep, manual penetration testing of web applications, REST APIs and mobile apps, including the AI and LLM features increasingly built into them. We look for the flaws that matter in a real system: broken authorization, tenant isolation failures, business-logic and workflow abuse, and chains of small issues that together become serious. Every reported finding is retested after your developers have fixed it.
How we work
Human-led testing, accelerated by our own platform, CybeRapid, which takes the repetitive work out of an engagement so more of our testers’ time goes on judgement: attack strategy, business context, and what actually matters to you. Reports are written for the engineers who have to fix the problem — reproduction steps, real impact and a concrete remediation, and we will defend any finding to the developers who wrote the code.
What we won’t do
We will not pad a report to look thorough, and we will tell you when a finding is not exploitable rather than bank the severity. We do not sell tools, training or managed services, and we will say so when a test is not what you need yet. A penetration test is only worth buying if you can act on the result.
- 500+Penetration tests delivered
- 15+Years of experience
- 6,500+Vulnerabilities found
- 300+Organisations secured
Our people
A small team of specialists
We hire for depth rather than headcount. People who have worked here have gone on to write tools the industry depends on and to found companies acquired by Snyk, Check Point, Contrast Security and Zimperium — that story is on our alumni page.
The company was founded in 2010 by Erez Metula, in the same year Syngress published his book on attacking managed runtimes. More about our founder.
What we test
The applications your business actually runs on
Web, API, mobile and AI-enabled applications — assessed by people who have been doing this since before there was an agreed methodology for most of it.
01
Web & API testing
Authenticated testing of complex applications and the APIs behind them.
See the service02
Mobile applications
iOS and Android, the data left on the device, and the backend they talk to.
See the service03
Authorization & isolation
Can one customer reach another’s data? The flaw class we are known for.
See the service04
AI & LLM features
Prompt injection, business-logic bypass, and models given too much authority.
See the service