New:Thread Pilot—AI follow-ups for Gmail.
Learn more

Switch Labs App Security

Application penetration testing with a report your team can use

Test your web application, APIs, and connected systems against an agreed scope. Get clear findings, a formal report for security reviews, and verification after fixes.

Built around your evidence request

For marketplace integrations, SaaS vendors, and teams preparing for customer security reviews. We define the test boundary with you before quoting or testing.

  • Web applications and APIs
  • Multiple user roles and accounts
  • Marketplace data paths
  • Confidential technical evidence

What the engagement includes

A report is useful only when its scope, evidence, and follow-up are clear. The exact assets and test methods are set in your statement of work.

Agreed scope

A written inventory of the applications, APIs, roles, environments, and connected systems to test, with exclusions recorded before work begins.

Application and API testing

Testing focused on access control, account boundaries, authentication, data exposure, and the risks relevant to your architecture.

Formal report

An executive summary and confidential technical findings with severity, supporting evidence, affected assets, and practical fixes.

Remediation verification

A follow-up test of reported findings, with a clear record of what was fixed, what remains open, and what could not be verified.

How it works

01

Share the request

Tell us which marketplace, customer, or security reviewer needs evidence and when it is due. Do not send credentials or sensitive data through the inquiry form.

02

Confirm the test boundary

We map the systems that handle the relevant data, agree on test accounts and safe environments, and document authorization and rules of engagement.

03

Test, report, and verify

We deliver a report tied to the agreed scope, discuss findings with your team, and verify fixes in a follow-up test.

Common questions

Can you test an Amazon SP-API application?

Yes. We can scope the systems that handle Amazon data and map the test to the evidence you were asked to provide. Amazon's annual penetration-test requirement can cover more than a web app or API, so the exact assets and deliverables are agreed before testing. Amazon decides whether submitted evidence meets its requirements.

Does a penetration test replace a Walmart security assessment?

A technical penetration test and a third-party security-program assessment are different engagements. We will review the exact request and, when a qualified third-party assessment is needed, coordinate a separate assessor rather than represent a test report as that assessment.

What do you need to prepare a quote?

A short description of the application, relevant integrations, the security review or marketplace request, the number of user roles and environments, and your target date. We will arrange secure access to technical material only after the scope and handling terms are agreed.

Request a test

Tell us what needs to be tested

Share the marketplace or customer request, the systems involved, and your target date. We will follow up to confirm scope and prepare a quote. Please do not include credentials or sensitive records here.

First step
Scope review
Pricing
Custom quote

By submitting you agree to let Switch Labs contact you about relevant products and services.