cyberagent.id · docs Service

Security Assessment

Offensive security testing of the systems you build and operate — web applications, APIs, external infrastructure, source code, and the attack surface of systems that rely on language models.

Assessment Types

AssessmentFocus
Web ApplicationAuthentication, authorization, injection, business logic, session management, application configuration
APIObject- and function-level access control, excessive data exposure, authentication, rate limiting, third-party integrations
Source Code ReviewLine-by-line review of the submitted code: authentication flows, input validation, secret handling, and trust boundaries
External InfrastructureInternet-exposed attack surface: service exposure, TLS configuration, headers, and undocumented entry points
Cloud & ConfigurationAccess policies, stored credentials, object storage, and recurring configuration errors
AI System ReviewPrompt injection, data leakage through the model, access control over knowledge bases, and agent integration security

Standards Coverage

Every assessment is mapped to the following frameworks. This mapping makes test results comparable across cycles and usable as internal compliance evidence.

FrameworkUsed for
OWASP Top 10The ten web application risk classes that form the testing baseline
OWASP API Security Top 10API-specific risks: BOLA, BFLA, mass assignment, resource consumption
OWASP LLM Top 10Risks in language-model-based systems: prompt injection, data leakage, agent abuse
OWASP ASVSVerification of application security controls at the level agreed during scoping
OWASP WSTGThe web application testing step guide that serves as our execution reference
MITRE ATT&CKMapping of attacker techniques and tactics for findings with detection implications
NIST CSF 2.0Placement of findings within the organizational risk management framework
ISO/IEC 27001Relevance of findings to the information security controls under audit
PTESTesting phase framework: scoping, intelligence, exploitation, reporting
CVSSMeasurable severity scoring for each finding, rather than scoring by impression

Deliverable

Evidence rule: a finding is included in the report only if it is demonstrated again from a clean state at the time of reporting. Findings that cannot be reproduced are dropped, not downgraded in severity.

Timeline

Duration is set during the scoping call — it depends on the number of assets, depth of review, and environment availability. The figures below are indicative only:

ScaleIndicativeBest suited for
Focused2–4 business daysA single application or API with a narrow scope
Standard5–10 business daysMultiple applications, APIs, and source code review
In-depth2–4 weeksMany assets, a large engineering team, or compliance objectives

Limitations

We do not perform: denial of service, high-volume stress testing, social engineering or phishing against employees, physical attacks, or testing of third-party assets without written authorization. For third-party systems connected to your assets, authorization must be arranged before testing begins.

Get Started

Request an Assessment
© 2026 CyberAgent.id Methodology · Custom AI · cyberagent.id