Some of our clients we can name. Most we cannot — penetration testing is done under NDA, and the organisations that most need it are the least able to say so publicly. Where we cannot give you a name, we give you the role and the sector instead, rather than a name we cannot evidence.

and from clients under NDA

They found an authorization bypass in our merchant portal that could have exposed transaction data for thousands of businesses. No scanner would have caught that — it required understanding our business logic.

Security ArchitectFintech infrastructure provider

They found a critical IDOR in our claims portal within the first two days. We had been live for 18 months without anyone catching it.

VP EngineeringDigital insurance platform

Their API security assessment covered edge cases we hadn’t thought of — broken object-level authorization, mass assignment, rate limiting gaps. The report read like a masterclass in API security.

Backend Team LeadDeveloper tools platform

We integrate with 200+ third-party APIs. AppSec Labs tested not just our code but how we handle upstream failures, malicious responses and credential rotation. That holistic view is rare.

CTOEuropean open banking platform

We process 50 million API calls per day. Their team tested our rate limiting, authentication and data validation at scale — not just with Burp Suite, but with custom scripts that simulated real attack patterns.

CTOUS API platform provider

Our clinical trial management system holds patient data subject to FDA 21 CFR Part 11. AppSec Labs understood the regulatory context and focused their testing on the areas that matter most for compliance.

VP Digital HealthPharmaceutical company

We needed SOC 2 compliance fast. AppSec Labs didn’t just run the pentest — they helped us understand which findings were blockers and which could wait, so we passed the audit on our first attempt.

Head of OperationsB2B SaaS startup

Our regulators required an independent penetration test. AppSec Labs delivered a report so detailed and well-structured that our compliance team uses it as a reference for every audit since.

VP CompliancePayment processing company

Every quote on this page comes from a real engagement. The two at the top are named with their permission; the rest are anonymised because our agreement with those clients requires it — not because there is anything vague about the work.

Want to know what we would find in your application? Talk to us — or read what 700 penetration tests actually find.