Umbra Penance
Service

Manual penetration testing for web apps, APIs and SaaS.

Find the vulnerabilities a scanner misses before a customer, auditor or attacker finds them for you. We test authentication, authorisation, business logic and tenant isolation, then give your developers evidence they can reproduce and fixes they can ship.

Cybersecurity assessment organising findings by business risk, likelihood and remediation priority.
01 / What we offer

What can we penetration test?

A clearly authorised assessment shaped around the assets, user roles and business risks that matter to you.

/ 01

Web application penetration testing

Authenticated user journeys, admin functions, sessions, file handling and business logic tested manually beyond a generic vulnerability scan.

/ 02

API penetration testing

REST, GraphQL and backend APIs assessed for broken authorisation, data exposure, injection, rate-limit weaknesses and abuse of intended functionality.

/ 03

SaaS and multi-tenant security

Tenant isolation, role boundaries, invitations, support tooling and privilege changes tested across the flows that can expose one customer's data to another.

/ 04

External attack surface review

Internet-facing services, cloud configuration and exposed administration paths reviewed to identify the routes an attacker is most likely to try first.

02 / The details

A penetration test your developers can act on.

Clear scope, manual validation and a direct route from confirmed finding to verified fix.

1 · Scope the assets, roles and rules

We agree the targets, test accounts, exclusions, production safeguards and success criteria in writing. A short threat-model session highlights the data and actions an attacker would value most.

External attack surface review covering application, API, cloud services and access paths.

2 · Test manually and validate the impact

Automated tools support coverage; they do not replace judgement. We test access controls, workflows and business logic manually, remove false positives and communicate critical findings immediately rather than waiting for the final report.

Prioritised security remediation plan organised by risk, effort and delivery horizon.

3 · Report, remediate and retest

You receive an executive summary and technical findings with evidence, impact and practical remediation guidance. We walk your developers through the report and verify agreed fixes during retesting.

Penetration testing report with validated findings, remediation status and retest results.
03 / When to test

Book a pentest when the result unlocks something important.

The strongest engagements start with a business reason and a deadline, not a vague instruction to ‘check security’.

Before a product launch

Test authentication, payments, sensitive workflows and administrative controls before real customer data reaches the platform.

Before an enterprise deal

Give a prospective customer or procurement team credible evidence that the application has received independent security testing.

For ISO 27001 or SOC 2 readiness

Support your risk treatment and assurance work with a defined scope, methodology, findings and remediation evidence.

After a major change

Reassess the attack surface after a new API, authentication provider, mobile app, cloud migration or significant change in user roles.

04 / Proof

Built by someone who understands the fix.

Security testing informed by hands-on software architecture, multi-tenant systems and production delivery.

ISO 27001 Lead Auditor

BSI-certified Lead Auditor training brings an assurance and risk-management lens to the technical assessment.

20+

tables under row-level security

Multi-tenant data isolation designed and enforced at the database layer on a production SaaS.

Builder + breaker

Recommendations come from someone who also architects and ships software, so the fix accounts for your codebase, release pressure and engineering trade-offs.

05 / Frequently asked questions

Penetration testing questions, answered.

What buyers and engineering teams usually need to know before approving a test.

How long does a web application penetration test take?

A focused web application or API assessment often takes several testing days, followed by reporting and a remediation walkthrough. The exact duration depends on user roles, functionality, API surface and the agreed depth. We confirm the effort after a short scoping call.

What is the difference between a vulnerability scan and a penetration test?

A scanner checks for recognisable technical patterns at scale. A penetration test adds manual investigation, authenticated workflows, access-control checks and business-logic testing, then validates whether a weakness is genuinely exploitable and what it means to the business.

Do you test production systems?

We can test production when that is the right environment, but only with written authorisation, agreed exclusions, safe test data and communication procedures. Where production risk is too high, we use a representative staging environment and confirm the important configuration differences.

What does the penetration testing report include?

The report includes scope and methodology, an executive summary, prioritised findings, evidence, affected assets, business and technical impact, reproduction guidance and recommended remediation. Critical issues are raised during testing rather than held until the report.

Can you help our developers fix the findings?

Yes. We include a technical walkthrough and practical remediation guidance, and we can support implementation where requested. Retesting verifies whether agreed fixes close the original issue without introducing a new weakness.

Start here

Bring us the bottleneck. Leave with a clear next move.

Send the context first or book a working session now. Either way, you'll get practical advice from the people who build and secure the systems.

Reply within one working day · No spam, no mailing list · No obligation

Prefer email? team@umbrapenance.com