Authorisation and role checks
Whether another user's record or another role's screen can be reached.
We hunt for authorisation, session and input-validation weaknesses on the OWASP Top 10 baseline.
This does not replace a penetration test; it targets the common and expensive mistakes in the application layer. Authorisation bypass, horizontal and vertical privilege escalation, session handling, insecure direct object references and input validation are the main focus.
38 check items
Whether another user's record or another role's screen can be reached.
Whether sign-out, a password change and expiry really end the session.
Server-side validation, file upload and query escaping.
Fields that should not appear in responses, logs or error pages.
No. It targets the common and expensive mistakes in the application layer. If regulation requires a pen test report, we will point you to an accredited firm.
Not required — we can work black box. With code access the results improve noticeably, especially on permission checks.
Only far enough to prove it exists. We do not exfiltrate data, do not leave changes behind, and log every attempt.
Sign up in the panel, pick what you want tested, pay. The first findings start landing in the same panel within hours.
SendTheCanary provides independent software testing for web, mobile and API products. Ten separate services from functional testing to payments and localization, run by a network of 4,700 testers and delivered as one report ranked by severity.
Services:Functional testingRegression testingCompatibility matrixPerformance & loadSecurity reviewAPI testingPayment testingAccessibilityUsability reviewLocalization testing