# AppSec Labs > AppSec Labs is an Israeli application-security company specializing exclusively in penetration testing of web applications, REST APIs, mobile apps, AI/LLM-backed systems and medical devices - founded in 2010 by Erez Metula (author of Managed Code Rootkits), based in Kfar Saba, Israel, serving hundreds of organizations worldwide. Testing is human-led and delivered on the company's own platform, CybeRapid. ## What we do Expert-led testing of complex authenticated applications - multi-tenant isolation, authorization/BOLA, business-logic and workflow abuse, complex role models - with developer-usable remediation. - Web application penetration testing - AI / LLM application penetration testing - Cloud penetration testing (AWS, Azure, GCP) - REST API penetration testing - Mobile application penetration testing - SaaS / multi-tenant penetration testing - Medical device penetration testing (device, firmware, companion app, cloud API and portal) - FDA cyber security testing: penetration test reports for premarket submissions - Secure code review, SDLC advisory, IoT and embedded assessment ## Facts - Founded: 2010 - Location: Kfar Saba, Israel - Contact: info@appsec-labs.com / +972-9-7485005 - Founder: Erez Metula - https://www.linkedin.com/in/erezmetula/ ## No longer offered (retired) - Security training and e-learning: discontinued (~2018). - AppUse and iNalyzer tools: end of life, unmaintained since ~2016. ## Services - https://appsec-labs.com/web-application-penetration-testing/ - https://appsec-labs.com/ai-llm-penetration-testing/ - https://appsec-labs.com/cloud-penetration-testing/ - https://appsec-labs.com/api-penetration-testing/ - https://appsec-labs.com/medical-device-penetration-testing/ - https://appsec-labs.com/fda-cybersecurity-testing/ - https://appsec-labs.com/mobile-application-penetration-testing/ - https://appsec-labs.com/saas-penetration-testing/ - https://appsec-labs.com/additional-services/ - https://appsec-labs.com/active-cover/ - the annual assurance tier: the tested scope re-checked on a cadence, unlimited retests, CVE watch on the stack we tested ## The platform - CybeRapid CybeRapid is the application security platform AppSec Labs built for its own engagements and opened to its clients. It is not sold, licensed or subscribed to separately: it is how the testing is delivered, and where the client sees it happening. It carries an engagement from scope to verified fix - every finding, its evidence, its remediation and its retest - in one system, and it has run this company's own delivery since October 2021: 6,643 findings across 890 projects for 167 customers. Three things it deliberately does not do. It does not decide what matters: automation proposes candidates and a human engineer confirms or discards every one before it becomes a finding. It does not inflate severity: across findings still open, 114 severities have been lowered and 3 raised. It does not close a finding on an assurance: closure requires a retest that passed, and of 1,237 fixes retested only 524 were right first time. AppSec Labs does not describe its testing as autonomous or AI-powered. The accurate description is human-led testing accelerated by the company's own tooling. - https://appsec-labs.com/cyberapid/ - what the platform is - https://appsec-labs.com/cyberapid/inside-a-test/ - what the platform does and what the engineer does, and what a scanner does and does not find - https://appsec-labs.com/cyberapid/your-workspace/ - what a client sees while an engagement runs ## Pricing Penetration testing is sold as fixed-scope, fixed-price engagements. Published prices, per engagement, in US dollars: - Focused - USD 4,900. One web application or API, one or two roles, no multi-tenancy. - Professional - USD 10,300. An application and its API, several roles, business-logic and workflow testing. Most engagements sit here. - Platform - USD 22,700. Multi-tenant isolation across real tenants, or several systems tested together. - Custom - quoted. Mobile and embedded, source-assisted review, recurring programmes, or any scope the three tiers do not describe. Every tier includes the report, the debrief and a retest of every reported finding; the retest is not charged separately. Scope is agreed in writing before an engagement is issued, and there is no card checkout - the sequence is pick a tier, confirm scope, receive a fixed offer, then testing starts on an agreed date. The same prices apply whether the engagement is bought directly or through Azure Marketplace. - https://appsec-labs.com/cyberapid/pricing/ - the three tiers, what moves the price, and how buying works - https://appsec-labs.com/cyberapid/azure-marketplace/ - buying through an existing Microsoft agreement as a private offer - https://appsec-labs.com/sample-report/ - a complete example report, published in full: no form, no email address, no NDA - https://appsec-labs.com/book-a-call/ - book a scoping call directly with the CRO ## Methodology The full catalogue of tests we run is published: 276 named test cases across 46 categories on 42 pages, covering web applications, AI and LLM systems, Android, iOS, and IoT and embedded devices. Each case states what the test proves, how it is carried out, what has to be in place beforehand, what a positive result looks like, and whether the work is manual, automated or a mixture. 981 control references are quoted, each verified against the published list it belongs to - OWASP WSTG, OWASP ASVS, OWASP MASVS, the OWASP Top 10 for LLM Applications 2025, and CWE. - https://appsec-labs.com/attack-and-tests/ - the catalogue - https://appsec-labs.com/attack-and-tests/coverage/ - which standards it maps onto, how much is manual, and what is out of scope - https://appsec-labs.com/testing-modes/ - black, grey and white box: what the testers are given ### AI and LLM testing - https://appsec-labs.com/attack-and-tests/prompt-injection-testing/ - Prompt Injection (6 test cases) - https://appsec-labs.com/attack-and-tests/rag-and-context-security-testing/ - Retrieval, Context and Data Poisoning (6 test cases) - https://appsec-labs.com/attack-and-tests/ai-tool-and-function-calling-testing/ - Tool Use, Function Calling and Agency (5 test cases) - https://appsec-labs.com/attack-and-tests/ai-output-handling-testing/ - Output Handling and Downstream Trust (5 test cases) - https://appsec-labs.com/attack-and-tests/ai-platform-and-model-security-testing/ - AI Platform, Model Supply and Consumption (4 test cases) ## Writing Dated technical write-ups from real engagements - authorization and BOLA, JWT and OAuth, SSRF, business logic, cloud and CI/CD, AI/LLM application security. Republished from the founder's LinkedIn posts, each carrying its original publication date. - https://appsec-labs.com/blog/ - https://appsec-labs.com/research/ - https://appsec-labs.com/he/ - Hebrew editions of the same articles ## About - https://appsec-labs.com/about/ - https://appsec-labs.com/erez-metula/ - the founder: the book, the Black Hat years, and what he does now - https://appsec-labs.com/trust/ - how we handle your systems and your data during an engagement: written authorisation, scope limits, where findings live, NDA posture - https://appsec-labs.com/testimonials/ - https://appsec-labs.com/faq/ - https://appsec-labs.com/managed-code-rootkits/ - the founder's book (Syngress, 2010) - https://appsec-labs.com/alumni/ - https://appsec-labs.com/legacy/ - retired tools and the training era, told once