Web Applications and APIs
Test authentication, authorisation, input handling, business logic and data-leakage risk.

SECURITY SERVICE
滲透測試(PT)
Authorised, controlled and clearly scoped testing to validate whether weaknesses can be exploited.
Scope, timing, technical limits and reporting procedures are agreed before testing begins.
Test authentication, authorisation, input handling, business logic and data-leakage risk.
Assess client-side behaviour, APIs, storage and transport security.
Identify exposed services, configuration gaps and potential attack paths.
Provide risk ratings, evidence, remediation guidance and agreed retesting.