Skip to content
Book a call

Home / Penetration testing services

Every surface, one team

Penetration Testing Services

We do one thing: penetration testing of software-based systems. Web applications, REST and GraphQL APIs, mobile apps, and the AI features increasingly built into them — tested by people who build software themselves.

AppSec Labs is an Israeli application-security company specializing exclusively in penetration testing of web applications, REST APIs, and mobile apps - founded in 2010 by Erez Metula (author of Managed Code Rootkits), based in Kfar Saba, Israel, serving hundreds of organizations worldwide.

Talk to us about thisSee a sample reportSee the test cases

What we test

Web application penetration testing

Authenticated, in-depth testing of complex applications — roles, workflows, business logic and multi-tenant isolation. Where one customer can reach another’s data, we find it.

AI & LLM application testing

Prompt injection, excessive agency, authorization through the model, and output that reaches a dangerous sink. We test what the model can be talked into doing.

API penetration testing

REST and GraphQL tested as first-class attack surface, not through the interface. Every endpoint against every role — including the endpoints your UI never calls.

Mobile application penetration testing

iOS and Android: the binary, the data left on the device, and the backend behind it — which is where the serious findings almost always are.

Medical device penetration testing

The device, its firmware, the companion app, the cloud API it reports to and the clinician portal — tested as one product, because that is what it is. Physical hardware is tested in our lab, and the report is built to go into an FDA premarket submission.

We also test cloud-hosted, IoT and embedded systems where the application layer is the target. The full methodology — 276 named test cases across 46 categories, each stating what it proves and how it is carried out — is published.

Why a developer-led team finds what others miss

Most security firms are staffed by security people who learned about software. We came at it from the other direction, and it shows in what we find.

  • We write code. Not scripts — software. We build and maintain CybeRapid, the platform our testers work on, in-house: the discovery, the role matrices, the evidence capture and the reporting are ours, and they improve because the people using them are the people writing them.
  • We read code the way its authors do. Our founder wrote Managed Code Rootkits (Syngress) about attacking the .NET CLR, the JVM and Android’s Dalvik — the layer underneath the application. Understanding a runtime that well changes what you notice in the application running on it.
  • We taught developers for a decade. Around 5,000 developers learned secure coding and application hacking from us, including five consecutive years teaching at Black Hat USA. It is why our reports are written for the person who has to fix the problem, and why we can defend a finding to the engineer who wrote the code.
  • Engineers who leave here build security products. People from this team went on to found companies acquired by Snyk, Check Point, Contrast Security and Zimperium — the pattern is documented.

This matters for one practical reason. The findings that decide a release are not pattern matches; they are consequences of how your system is built — a role model with an exception in it, a workflow that can be reordered, an API that trusts a value it should have recalculated. Recognising those requires reading a system the way an engineer does, then attacking it the way an adversary does.

How an engagement works

  1. Scoping — fixed scope, timeline and price, not an open-ended engagement.
  2. Testing — hands-on-keyboard work by experienced testers, accelerated by CybeRapid so more of our time goes on judgement.
  3. Reporting — reproduction steps, real impact and a concrete fix for every finding. Severity rated by what an attacker can actually achieve in your system.
  4. Remediation support — we walk your developers through it and review the fixes.
  5. Retest — every reported finding verified after the fix, as part of the engagement.

Compliance and customer security reviews

Our reports are regularly used to satisfy enterprise security reviews and regulatory expectations including SOC 2, PCI-DSS, HIPAA and FDA submissions. Tell us which framework or customer questionnaire you are answering and we will make sure the report addresses it.

Beyond testing

Testing is our focus, but it is not the only way we work with engineering teams. Where it helps we also review source code, advise on secure development practices and run threat modelling sessions — more on those here.

Talk to us about testing your application

Expert-led testing of complex authenticated applications - multi-tenant isolation, authorization/BOLA, business-logic and workflow abuse, complex role models - with developer-usable remediation.

Tell us what the application does and what worries you about it. We will come back with scoping questions, a clear proposal and a realistic timeline — and if a test is not what you need yet, we will say so. Get in touch.

Book a scoping callSee a sample reportWhat clients say