Set the scope
List the approved domains, environments, accounts, roles, and actions Casco must avoid. Add source code or infrastructure access only if it is part of the test.
Casco signs in with test accounts, uses the workflows in scope, and records the pages, endpoints, WebSockets, and requests it encounters. It then checks whether a user can cross a role or tenant boundary, change data they should not control, or abuse an application-specific workflow.
Web application pentesting checks a running product for vulnerabilities that can be reached through the browser or the services it calls. Casco tests only the approved domains, accounts, roles, and workflows. Confirmed findings include the affected resource, impact, fix guidance, and steps an engineer can rerun.
How Casco tests
Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.
List the approved domains, environments, accounts, roles, and actions Casco must avoid. Add source code or infrastructure access only if it is part of the test.
Casco signs in with the provided accounts and records pages, endpoints, WebSockets, screenshots, DOM state, cookies, console output, and network requests.
Casco changes roles, object references, inputs, and request sequences to check authorization, tenant isolation, session handling, file processing, and business logic.
Each confirmed issue can include the affected resource, impact, fix guidance, a runnable reproduction notebook, execution output, and captured requests when request tracking is available.
Pentest deliverables
The report states what Casco tested, how the test was run, what was confirmed, and what engineers need to fix.
Learn more
Read how Casco confirmed and disclosed a database-impacting web API vulnerability during an approved test.
Read the sourceCompare fixed checks, scanner validation, manual testing, and Casco agent testing.
Read the sourceReview Casco's penetration testing accreditation and how human-attested supervised testing fits.
Read the sourceChecks included when applicable
Casco reports an issue only after it confirms the behavior. The exact finding includes the affected resource, impact, fix guidance, and available reproduction material.
Related testing
Frequently asked questions
AI web application pentesting uses software agents to operate a web application and choose the next security test from what they observe. Casco signs in with approved test accounts, uses the application, changes requests and inputs, and reports vulnerabilities it can reproduce.
A scanner runs a catalogue of checks and often reports possible issues. Casco uses the application, follows logged-in workflows, changes its tests based on the responses, and reports issues it can confirm.
Yes. Provide test accounts for each role or tenant boundary you want included. Casco uses those accounts only within the approved scope.
Yes. Casco can compare roles and tenant accounts and test application-specific workflows when the required accounts and objects are available.
Casco needs the approved domains, rules of engagement, and test accounts for logged-in coverage. Some environments also need Casco IP addresses on an allowlist. Documentation, source code, and infrastructure access are optional unless the scope requires them.
Casco can record pages, endpoints, WebSockets, screenshots, DOM state, cookies, console output, network requests, and the user flows it followed.
A finding can include severity, the affected resource, impact, fix guidance, a runnable reproduction notebook, execution output, and captured requests when request tracking is available.
Yes. Casco records whether a finding is still exploitable, being retested, fixed, or accepted as risk.