Switch Labs App Security
Application penetration testing with a report your team can use
Test your web application, APIs, and connected systems against an agreed scope. Get clear findings, a formal report for security reviews, and verification after fixes.
Built around your evidence request
For marketplace integrations, SaaS vendors, and teams preparing for customer security reviews. We define the test boundary with you before quoting or testing.
- Web applications and APIs
- Multiple user roles and accounts
- Marketplace data paths
- Confidential technical evidence
What the engagement includes
A report is useful only when its scope, evidence, and follow-up are clear. The exact assets and test methods are set in your statement of work.
Agreed scope
A written inventory of the applications, APIs, roles, environments, and connected systems to test, with exclusions recorded before work begins.
Application and API testing
Testing focused on access control, account boundaries, authentication, data exposure, and the risks relevant to your architecture.
Formal report
An executive summary and confidential technical findings with severity, supporting evidence, affected assets, and practical fixes.
Remediation verification
A follow-up test of reported findings, with a clear record of what was fixed, what remains open, and what could not be verified.
How it works
Share the request
Tell us which marketplace, customer, or security reviewer needs evidence and when it is due. Do not send credentials or sensitive data through the inquiry form.
Confirm the test boundary
We map the systems that handle the relevant data, agree on test accounts and safe environments, and document authorization and rules of engagement.
Test, report, and verify
We deliver a report tied to the agreed scope, discuss findings with your team, and verify fixes in a follow-up test.
Common questions
Can you test an Amazon SP-API application?
Yes. We can scope the systems that handle Amazon data and map the test to the evidence you were asked to provide. Amazon's annual penetration-test requirement can cover more than a web app or API, so the exact assets and deliverables are agreed before testing. Amazon decides whether submitted evidence meets its requirements.
Does a penetration test replace a Walmart security assessment?
A technical penetration test and a third-party security-program assessment are different engagements. We will review the exact request and, when a qualified third-party assessment is needed, coordinate a separate assessor rather than represent a test report as that assessment.
What do you need to prepare a quote?
A short description of the application, relevant integrations, the security review or marketplace request, the number of user roles and environments, and your target date. We will arrange secure access to technical material only after the scope and handling terms are agreed.
Request a test
Tell us what needs to be tested
Share the marketplace or customer request, the systems involved, and your target date. We will follow up to confirm scope and prepare a quote. Please do not include credentials or sensitive records here.
- First step
- Scope review
- Pricing
- Custom quote