An API Assessment is a focused, founder-led review of APIs your organisation owns. It looks at how callers prove who they are, whether object-level access holds up, how much data responses return, and the common misconfigurations that leave APIs more open than intended — then turns that into a clear picture of exposure and fixes your team can act on.
This sits alongside Web, External Infrastructure, OSINT and Firewall as one of five services. Choose API when the interface that matters is a machine-facing contract — mobile backends, partner integrations, internal services exposed over HTTP, or public API products — rather than a full website review or an internet-wide host map.
What it is
We examine authentication and session patterns, object-level access (whether one caller can reach another user’s or tenant’s data), excessive data exposure in responses, and frequent API misconfigurations such as weak rate limits, verbose errors, permissive CORS, undocumented or forgotten endpoints, and broken function-level access controls.
The emphasis is practical: evidence where it helps, business impact in plain English, and remediation steps an engineering team can schedule. It is not a look at third-party APIs you do not control, and it is not a substitute for a full programme across every system you run.
Who it is for
UK startups, SMEs, agencies and SaaS teams whose product or operations depend on APIs they own. Product teams preparing for customer security questions often start here when the API is the main surface. Agencies commissioning work for a client should involve that client in authorisation.
If your loudest question is a marketing site or portal UI, Web may be the better first step. If you need to map what is reachable on the internet before naming an API, External Infrastructure often comes first. If the worry is public phishing fuel or messy firewall rule bases and configuration files, OSINT or Firewall may fit better.
What we need
Someone who can authorise testing. A list of API bases, environments and versions in scope. Clarity on production versus staging. Test credentials or tokens if authenticated areas matter. Notes on rate limits, fragile routes and third-party components that sit outside bounds. An emergency contact if something needs to stop.
Scope and prerequisites are locked before work starts so the assessment stays finishable and fair to your production systems.
What you get
Prioritised findings with the highest-impact issues first. Evidence such as request or response excerpts where appropriate. Plain-English risk context. Practical remediation steps. A debrief call to walk through the report. An optional retest after you have fixed what matters.
You also get founder-led continuity: the person who scoped and tested is the person explaining the results.
Boundaries we keep
Work stays on APIs you own. Third-party or competitor APIs without permission sit outside this service. A focused API pass is not every possible security activity for the business — if Infrastructure, Web, OSINT or Firewall would answer the real question better, we will say so as a recommendation rather than stretching the label.
How it fits the 3-call process
Free intro call to confirm API is the right starting point. Scope and prerequisites call to lock authorisation and assets. Assessment and report. Debrief call to turn findings into actions. That rhythm keeps SME engagements finishable.
Example starting scenarios
A mobile app backend that grew quickly. A partner integration that now carries customer data. An internal API that became internet-reachable. A SaaS product facing diligence questions about object access and data leakage. In each case, a focused API Assessment gives you something concrete to fix and something concrete to show.
On the free intro call we will sanity-check whether API is truly first, or whether Web or External Infrastructure should come ahead. That sequencing advice is part of founder-led delivery.
Fit with the rest of the site
API Assessment is one of five services. Many buyers arrive unsure whether their issue is an application UI problem, an API contract problem, or an exposure problem. That is a normal starting point. We would rather redirect you to the right review than force an API engagement that answers the wrong question.
After delivery, optional retest helps confirm that authentication fixes, access-control changes and exposure reductions actually landed. Pair that with the debrief so non-technical stakeholders understand what “done” means.
Before testing starts
Free intro is a fit conversation — written authorisation and a locked scope come before any testing.
Ready to talk it through?
Book a free intro call to confirm fit, authorisation and scope. Prefer the form? Use the contact section on the main site.
Also see: Web Assessment · External Infrastructure · OSINT · Firewall Review · Start here
Out of scope for API
API Assessment covers APIs you own. It is not a review of third-party APIs, not internet-wide discovery (use External Infrastructure), not public phishing-exposure mapping (use OSINT), not firewall rule bases and configuration files tidy-up (use Firewall), and not a full website UI review where Web is the better fit.