Testing with limited information and standard user accounts — the approach we recommend for most applications, balancing the realism of black-box with the coverage of white-box for the best value.
Grey-box penetration testing is the pragmatic middle ground. We work with standard user accounts and limited documentation — enough to test authenticated functionality and authorisation thoroughly, while still exercising the realism of an attacker who has gained a foothold.
For most web, API, and mobile applications it delivers the most issues found per day of effort, which is why it is our default recommendation.
Limited-knowledge, authenticated testing that balances realism and depth.
The questions we're asked most about scope, cost, and timing.
A 30-minute scoping call costs nothing. A breach costs considerably more.
Book a meeting Send an email