Web Application Pentest Requirement
🔴 Required (Must Provide):
- Web Application URL(s) (ex: app.company.com)
- Information on whether the environment is staging or production
- The Web Application API endpoint (ex: api.company.com) Required if the client wants the API examined (assumed yes)
- Credentials for all roles that need to be tested. (ex: Owner, Administrator, Team Administrator, normal user, customer, client, etc. ), We recommend two sets of credentials per role.
⭐ Optional but recommended:
- Documentation or List of the API endpoints (ex: Swagger doc, Postman collection, etc.)
- Demo of the APP functionalities and brief explanation of the business logic
💡 Recommended:
- Pre-loaded dummy data where applicable.