SANITY-CHECK YOUR WEB APPS

Web Application Penetration Testing in Saudi Arabia

Manual, expert testing for OWASP Top 10:2025 vulnerabilities — IDOR, XSS, authentication bypass, and business logic flaws — with proof-of-concept evidence your team can act on. Delivered in Arabic or English, reports mapped to SAMA / NCA / ISO 27001 when you need compliance evidence.

What's covered

Beyond automated scanning

Tools miss the flaws that actually matter. Every engagement is tested manually, exploiting what a real attacker would target — then proven with reproduction steps and proof-of-concept evidence.

IDOR & broken access controlCan users read or modify others' data by tweaking IDs and object references?
XSS (stored, reflected, DOM)Script injection that hijacks sessions or defaces what your customers see.
Authentication bypassSession flaws, weak password handling, missing 2FA, privilege escalation paths.
Business logic flawsAbuse of workflows, pricing, limits, and state — the flaws scanners never find.
SQL injection & injection classesQuery injection that can expose or destroy your database.
SSRF, CSRF, mass assignmentServer-side and request-level abuse specific to your architecture.
How it works

A clear process, no black boxes

  1. Free scoping call — 30 minutes to understand your environment, goals, and anything off-limits. You get a fixed quote and timeline before work begins.
  2. Targeted testing — manual and structured testing within the agreed scope, with progress updates along the way.
  3. Report & prioritisation — findings ranked by business risk, with reproduction steps, PoC evidence, and practical fix guidance.
  4. Retest & closure — after your team applies fixes, every finding is retested to confirm resolution and no regressions.
AssessmentStarting priceTypical timeline
Web Application PentestSAR 7,5004–10 working days
Vulnerability Assessment (first check)SAR 3,5002–4 working days
Retest & remediation verification30% of original (from SAR 2,500)Within 3 months

Prices are estimated starting points — final quotes are confirmed after the free scoping call. VAT not included.

Want a feel for the deliverable?

Preview a sample penetration test report before you commit — illustrative, with fictional client data.

View Sample Report
FAQ

Common questions, straight answers

What does a web application penetration test include?

Manual testing for OWASP Top 10:2025 issues — IDOR, XSS, authentication bypass, business logic flaws and more — with full proof-of-concept documentation and practical remediation guidance.

How long does a web pentest take?

Most assessments complete in 4–10 working days depending on scope. You receive a confirmed timeline during the free scoping call, before any commitment.

Do you sign an NDA and test production safely?

Yes. An NDA is signed before testing begins, and a rules-of-engagement document defines scope, testing windows and authorised techniques so your systems are tested safely.

Can the report serve as compliance evidence?

Yes. Testing follows OWASP Top 10:2025 and NIST SP 800-115, and reports can be mapped to the SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls (ECC), or ISO 27001:2022.

Is a retest included?

Yes. After fixes are applied, every finding is retested to confirm it is resolved and no regressions were introduced.

Ready to check your web app?

Start with a free, no-obligation scoping call — Mohammed replies within 24 hours, often much faster on WhatsApp.

Chat on WhatsApp +966 56 215 5628