Web Application Penetration Testing

Simple. Predictable. Pay as You Go.

ImmuniWeb® On-Demand leverages our proprietary Multilayer Application Security Testing technology for rapid, reliable and DevSecOps-enabled web penetration testing. It combines our award-winning Machine
Learning and AI technology with scalable and cost-effective manual web security testing.

ImmuniWeb® On-Demand

In-Depth Testing
In-Depth Testing

coverage & business logic testing

Accurate Reporting
Accurate Reporting

Zero false-positive SLA and actionable remediation guidelines

DevSecOps Tailored
DevSecOps Tailored

One-click WAF virtual patching,
SDLC & CI/CD integration

How It Works

  1. Pick up a web
    application or API
  2. Customize, pay and
    schedule the test
  3. Download your
    remediation report

Standards & Methodologies

We leverage in-house application security testing methodologies in combination with:

  • OWASP Testing Guide
  • NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
  • PCI DSS Information Supplement: Penetration Testing Guidance
  • FedRAMP Penetration Test Guidance
  • ISACA’s How to Audit GDPR
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
PCI DSS Information Supplement: Penetration Testing Guidance
FedRAMP Penetration Test Guidance
OWASP Testing Guide

We follow international standards to report security vulnerabilities:

  • Common Vulnerabilities and Exposures (CVE) Compatible
  • Common Weakness Enumeration (CWE) Compatible
  • Common Vulnerability Scoring System (CVSSv3)
Common Vulnerabilities and Exposures (CVE) Compatible Common Weakness Enumeration (CWE) Compatible Common Vulnerability Scoring System (CVSSv3)

Comprehensive Penetration Testing

Internal & External Web Apps

Virtual Appliance technology for
internal applications testing

APIs and Web Services

Comprehensive coverage of API &
Web Services (REST/SOAP)

Open Source Security

Software Composition Analysis (SCA)
tests for 20,000+ known CVE-IDs

Vulnerability Coverage Datasheet

  • Injection Flaws

  • Many other "High" Risk Vulnerabilities

  • Buffer Overflows

  • Cross-Site Scripting (XSS)

  • Insecure Cryptographic Storage

  • Improper Access Control

  • Insecure Communications

  • Cross-Site Request Forgery (CSRF)

  • Improper Error Handling

  • Broken Authentication and Session Management

DevSecOps Integrations

Developers Environment

Jira DevSecOps Integration HP DevSecOps Integration Bugzilla DevSecOps Integration Splunk DevSecOps Integration Mantis DevSecOps Integration Defectdojo DevSecOps Integration

Web Application Firewalls

Testimonials and Customer References

Crédit Agricole next bank (Suisse) SA
eBay Classifieds Group
Haymarket Media, Inc.
Swissquote Bank SA
University Hospitals of Geneva (HUG)
SIX Group Services AG
International Telecommunication Union (ITU)
Banca dello Stato del Cantone Ticino
SIM University
Arab Bank (Switzerland) Ltd.
Legal Vision

ImmuniWeb® On-Demand Pricing

all included
½ day of team
penetration testing
all included
1 day of team
penetration testing
Corporate Pro
all included
5 days of team
penetration testing
Best Choice
all included
3 days of team
penetration testing
1 Testing
  • Instant Start
  • Suits to test several domains / URLs
  • Multilayer Application Security Testing:
    • Threat-aware testing scenarios
    • AI to reduce human testing and analysis
    • Machine Learning to accelerate testing
    • REST/SOAP API testing
    • Authenticated testing
    • 2FA & SSO support
  • Full customization of testing
2 Reporting
  • Rapid delivery SLA
  • Zero False-Positive SLA
  • Threat-Aware Risk Scoring
  • Tailored Remediation Guidelines
  • Web Interface, PDF and XML Formats
  • PCI DSS and GDPR compliances
  • CVE, CWE and CVSSv3 scores
3 Remediation
  • 24/7 Access to Our Security Analysts
  • Integration With SDLC & CI/CD Tools
  • One-Click Virtual Patching via WAF
  • Unlimited Patch Verifications
  • Multirole Dashboard

Frequently Asked Questions

The main difference is the amount of human time spent on a project to detect the most complicated, untrivial and novel security vulnerabilities. All other options and features are the same.

For every project we have several security analysts conducting advanced manual testing. Thanks to our AI-enabled multilayer application security testing technology, our security analysts spend their time only when and where it is truly needed due to complexity (e.g. bypassing WAF, running a chained exploitation or analyzing business logic flaw).

You can include as many of them as practical. We recommend aggregating URLs only if they belong to the same application, for example, your ERP or e-banking system may be located across several (sub)domains and have numerous APIs - all of them can be included into one package. Likewise, it will be inappropriate to group your CRM and unrelated Partner Portal in one package.

It is a contractual clause for every project. The following delivery schedule is guaranteed upon start:

  • 2 business days for Express and SMB
  • 4 business days for Corporate
  • 6 business days for Corporate Pro

It is a contractual clause for every project. It clearly stipulates that for one single false positive in your report you will get back the amount paid for the assessment.

When creating a project you can specify in plain English any special requirements for testing and remediation. Just say to focus on 2FA bypass, avoid reporting low-risk XSS or provide in-depth remediation for PHP developers – and we will do so.

We provide actionable remediation guidelines for each of the detected vulnerabilities. Moreover, you have unlimited access to our security analysts might you have any further questions. We also offer one-click virtual patching via WAF of F5, Imperva, Fortinet, Barracuda, DenyAll and many others. All this at no additional cost.

In addition to interactive, multi-role dashboard you can get your report in PDF and XML formats. Available XML schemas are export-ready for all popular developers tools such as Jira.

All ImmuniWeb customers get unlimited access to our security analysts via ImmuniWeb Portal. You can ask questions about exploitation, remediation or any other project-related topics.

You can run unlimited re-assessments at no additional cost to verify whether all previously detected vulnerabilities were properly patched. Available 60 days after report delivery.

All penetration testing data is securely stored in our ISO 27001 infrastructure in Canada and Switzerland (both recognized by the European Commission as countries providing an adequate level of data protection for the purpose of GDPR). For most of the projects we automatically delete the data 90 days after report delivery. Upon request all data can be deleted at any moment.

You may create as many user accounts as practical and grant them flexible, role-based access permissions.

Yes, please just specify in special requirements to your project that your website was hacked and will try to investigate how it happened in addition to security testing.

You can start right now, we accept all types of online payments – PayPal, Credit Cards and Bank Wire (usually takes 2-3 business days). If your project is urgent, please create a support ticket and will try to start it immediately.

Any other questions? Contact Sales

Gartner Peer Insights Recommends

Gartner Peer Insights
Quick Start
Get a Demo