API penetration testing that finds what scanners miss

A certified engineer from our SOC tests your APIs and microservices remotely with real attacker tradecraft mapped to MITRE ATT&CK, then hand-writes your report. Free remediation retest included.

Since 1998
Managed security
PCI ASV
Since 2007
MITRE ATT&CK
Aligned tradecraft
Free Retest
After remediation
What We Test

Every endpoint, tested by a real engineer.

REST, GraphQL and gRPC APIs and the microservices behind them.

REST, GraphQL & gRPC

APIs and microservices across all three styles.

Broken Authentication & BOLA

Broken authentication and broken object level authorization.

Mass Assignment

Fields and properties that should never be writable.

Rate-Limit Bypass

Ways around throttling and abuse protections.

Injection

Injection flaws through API parameters and payloads.

Data Exposure & Logic Abuse

Excess data in responses and business-logic abuse.

Faster option. Automated pen tests include testing of supported APIs behind your web app.

See automated pricing
How It Works

Scoping call to passing retest in six steps.

Expert-led and delivered remotely by a certified engineer from the Clone Systems SOC.

01

Scoping & SOW

A scoping call and a fixed statement of work with no surprise fees.

02

Engineer Kickoff Call

Your engineer confirms targets, credentials, rules of engagement, blackout windows and escalation contacts.

03

Active Testing

Your engineer tests remotely from our SOC with real attacker tradecraft mapped to MITRE ATT&CK.

04

Reporting

A hand-written report from the engineer who ran your test, with evidence and remediation.

05

Remediation Window

You fix the findings. Your engineer stays available for questions.

06

Free Remediation Retest

We retest in-scope findings and issue an updated retest report to prove closure.

Engineer Kickoff Call

Every test starts with a real conversation.

After the scoping call and a fixed statement of work, you meet the certified engineer running your test before testing starts.

  • Confirm targets. Exactly what is in scope and what is not.
  • Verify credentials. Access for authenticated testing is confirmed up front.
  • Agree rules of engagement. Testing windows, blackout windows and escalation contacts.
  • Meet your engineer. You know who is running your test and how to reach them.
Kickoff Call · Agenda
01
Introductions and assigned engineer
02
Targets and credentials
03
Rules of engagement
04
Blackout windows
05
Escalation contacts
06
Confirm start date
Your engineer stays reachable through the engagement.
Deliverables

A real report, written by your engineer.

Your final report is hand-written by the engineer who ran the test, not an auto-generated export. See what is in a pen test report.

Engineer-Written Executive Summary

Written by the engineer who ran your test.

Technical Findings & Proof-of-Exploit

Reproduction steps, severity and remediation for every issue.

Auditor-Ready PDF

Share with auditors, customers and cyber insurance underwriters.

Remediation Retest Report

A free retest of in-scope findings and an updated report to prove closure.

Who It Is For

Built for teams that need audit-defensible proof.

SaaS & Platform Companies

Proof for enterprise customers that your APIs were tested by an engineer.

Microservice Architectures

Testing across services, not just the public front door.

Regulated Organizations

Evidence for PCI DSS 4.0.1 Requirement 11.4, HIPAA, SOC 2, ISO 27001 and FedRAMP.

Cyber Insurance Renewals

An engineer-written report and retest report to share with your underwriter.

Compliance Evidence

Reports that hold up in an audit.

Clone Systems has provided managed security since 1998 and has been a PCI Approved Scanning Vendor since 2007, based in Philadelphia, PA.

PCI DSS 4.0.1

Supports Requirement 11.4 penetration testing.

HIPAA, SOC 2, ISO 27001

Independent, engineer-written evidence for your auditors.

FedRAMP & Cyber Insurance

Reports and retest reports for assessments and renewals.

READY TO SCOPE YOUR TEST

Talk to a specialist, get an honest scope.

Tell us what you need tested. We will set up a scoping call and send a fixed statement of work with no surprise fees.

  • Certified engineer from our SOC on every test
  • Kickoff call before testing begins
  • Engineer-written report, not an auto-generated export
  • Free remediation retest of in-scope findings
GET A QUOTE

Scope an API Pen Test

Tell us what you need tested and who is asking for the report. We will set up a scoping call and a fixed statement of work. All fields required.

No spam, ever.

API Penetration Testing FAQ

API Penetration Testing, answered.

Not sure which test you need? Take the pen test finder.

What does a pen test cost? See penetration test pricing.