SysTools logoSysTools VAPT
VAPT Service

API VAPT

Security testing of the APIs behind your website, mobile app and partner connections — checking logins, permissions, data handling and business rules. Please answer what you can; anything you are unsure of can be settled on the scope call.

Progress 0% 0 of 0 answered 0 mandatory pending

Before you start

  • Please do not type real passwords, API keys or tokens into this form. Those are shared separately through a secure channel.
  • We only test the APIs you list here. Fields marked * are needed before testing can begin.
  • If you are not sure about something, pick "Not sure" or leave a note — we will go through it with you on the scope call.

1 Assessment Details

Mandatory

2 Scope and Testing Approach

Mandatory

Grey Box — you give us login details and basic documents. White Box — you also share the design and technical details. Black Box — we start with nothing, so more of the time goes into finding things rather than testing them.

Please note: this is not included in the timeline estimate in section 10. The estimate covers one round of testing only. How often it repeats is agreed when the scope is finalised.

3 API Details

Decides the timeline

Rough numbers are fine. Leave anything blank if it does not apply.

The API

APIs or services in scope
API endpoints, approximate
User roles or permission levels

Features

Admin-only endpoints
File upload or download endpoints
Payment or money-movement endpoints

Connections

Third-party or partner integrations
Webhooks or callbacks
Login / SSO integrations

An endpoint is one action the API can perform — for example "get user details" or "create order".

We only test the addresses listed here.

If yes, we check that one customer cannot see another customer's data.

4 Access and Login

Needed before we can start

Without a login for each role we cannot check whether one user can reach another user's data — the most common serious API problem.

Two accounts in the same role let us prove whether one user can see the other's data.

5 Test Environment and Restrictions

Mandatory

Anything you do not allow here will not be tested.

If it stays on and keeps blocking us, the report ends up describing the firewall instead of the API.

What is included as standard

Every API VAPT includes automated scanning, login and access checks, injection testing, permission and role checks, business logic testing, file upload testing, and controlled follow-up on anything we confirm as a real issue. You do not need to select these.

This is a controlled assessment limited to the scope you approve, not a red-team exercise. It does not include phishing, social engineering, physical security testing, or attempts to stay hidden inside your network.

6 Data and Standards

Affects how serious a finding is

7 What We Will Test

All included by default

Everything below is included. Untick anything you want left out.

8 How We Run the Assessment

A mix of automated tools and manual testing, adjusted to your API, the roles available and the access you provide.

01

Confirm scope and access

We agree the API addresses, environment, user roles, login details, testing dates and any restrictions, and confirm written authorization before starting.

02

Gather information

We look at how the API is built and hosted, what it returns, which security settings are in place, and which endpoints and integrations exist.

03

Map the API

We go through each endpoint by hand — what it does, what it accepts, which role can use it, and how it fits into your business workflows.

04

Automated checks

Scanning for known weaknesses, weak encryption, missing security settings and outdated components. Everything a tool reports is checked by a person before it goes in the report.

05

Manual testing

Logins, permissions, input handling, data exposure, request limits, file handling and connections to outside systems — the checks tools cannot do reliably.

06

Business logic testing

We check whether normal features can be misused: skipping steps, changing amounts, reusing coupons or expired links, or repeating completed transactions.

07

Confirm each finding

We reproduce every issue, note the affected endpoint and role, and capture evidence. We use the least intrusive method that proves the problem, and avoid anything destructive.

08

Report and retest

Each finding is rated and written up with clear fix guidance. Once you have made the fixes, we retest and update the status.

Anything urgent is reported immediately

If we find something serious — a login bypass, admin account takeover, exposed keys or access to all customer records — we tell you straight away rather than waiting for the final report.

9 How We Rate Findings

SeverityWhat it means
CriticalCould give an attacker full control of the API, the database or the server, or expose sensitive data at scale. Fix immediately.
HighCould let an attacker take over accounts, reach data they should not see, or gain higher privileges.
MediumA real problem, but it needs certain conditions, a valid login or some user action to work.
LowLimited impact on its own. Worth fixing as part of normal improvement work.
InformationalAn observation or good-practice suggestion. Not directly exploitable.

After a retest each finding is marked Closed, Open, Partially Fixed, Risk Accepted or Not Retested.

10 Timeline Estimate

The API and endpoint counts are carried over from section 3 automatically.

Timeline inputs

Number of APIs
API endpoints
Parallel testing teams
Number of retests

One retest is included as standard. Increase this only if additional retest cycles are required.

Estimated duration 0 working days
Testing0
Retest0

Subject to final scope review, access availability and resource confirmation. The final timeline is confirmed after the complete scope has been reviewed and understood.

Save and Export Response

Your answers stay in this browser until you export or clear them.