Software Secured Company Logo.
Services
Services
WEB, API & MOBILE SECURITY

Manual reviews expose logic flaws, chained exploits, and hidden vulnerabilities

Web Application Pentesting
Mobile Application Pentesting
Secure Code Review
Infrastructure & Cloud Security

Uncovers insecure networks, lateral movement, and segmentation gaps

External Network Pentesting
Internal Network Pentesting
Secure Cloud Review
AI, IoT & HARDWARE SECURITY

Specialized testing validates AI, IoT, and hardware security posture

AI Pentesting
IoT Pentesting
Hardware Pentesting
ADVANCED ADVERSARY SIMULATIONS

We simulate attackers, exposing systemic risks executives must address

Red Teaming
Social Engineering
Threat Modelling
PENETRATION TESTING AS A SERVICE

PTaaS provides continuous manual pentests, aligned with release cycles

Penetration Testing as a Service
OWASP TOP 10 TRAINING

Practical security training strengthens teams, shifting security left effectively

Secure Code Training

Ethical Hacking

Services Overview

Black arrow icon

Enterprise Deal Support

Services Overview

Black arrow icon
Ready to get started?
Identify real vulnerabilities confidently with zero-false-positive penetration testing
Learn More
Industries
Industries
INDUSTRIES
Data and AI

AI pentesting uncovers adversarial threats, ensuring compliance and investor trust

Healthcare

Penetration testing protects PHI, strengthens compliance, and prevents healthcare breaches

Finance

Manual pentests expose FinTech risks, securing APIs, cloud, and compliance

Security

Penetration testing validates SecurTech resilience, compliance, and customer trust

SaaS

Pentesting secures SaaS platforms, proving compliance and accelerating enterprise sales

CASE STUDY

“As custodians of digital assets, you should actually custodize assets, not outsource. Software Secured helped us prove that our custody technology truly delivers on that promise for our clients in both the cryptocurrency and traditional finance”

Nicolas Stalder,
CEO & Co-Founder, Cordial Systems
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Compliance
Compliance
COMPLIANCE
SOC 2 Penetration Testing

Pentesting validates SOC 2 controls, proving real security to auditors and customers

HIPAA Penetration Testing

Manual pentesting proves HIPAA controls protect PHI beyond documentation

ISO 27001 Penetration Testing

Pentests uncover risks audits miss, securing certification and enterprise trust

PCI DSS Penetration Testing

Pentesting validates PCI DSS controls, protecting sensitive cardholder data

GDPR Penetration Testing

GDPR-focused pentests reduce breach risk, regulatory fines, and reputational loss

CASE STUDY

“Software Secured’s comprehensive approach to penetration testing and mobile expertise led to finding more vulnerabilities than our previous vendors.”

Kevin Scully,
VP of Engineering, CompanyCam
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
PricingPortal
Resources
Resources
resources
Blogs
Case Studies
Events & Webinars
Partners
Customer Testimonials
News & Press
Guides and Checklists
About Us
cybersecurity and secure authentication methods.
Black arrow icon
API & Web Application Security Testing

Attack Chains: The Hidden Weakness in Modern API & Web Application Security

Alexis Savard
November 21, 2025
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Login
Book a Consultation
Deal Blocked?
Guides and checklists
/
Checklists

Pentest Scoping Checklist

Before requesting quotes, security teams should inventory API endpoints, GraphQL operations, authentication methods, user roles, integrations, and infrastructure dependencies that affect testing effort. This checklist helps SaaS teams arrive at a scoping call with the information needed to estimate pentest scope, timelines, and cost more accurately.

Download document

Key Takeaways

  • API endpoints and GraphQL operations are the most reliable units for estimating pentest scope.
  • REST API counts should be based on OpenAPI specifications, route dumps, traffic captures, or feature estimates when necessary.
  • Authentication methods such as SSO, MFA, API keys, and magic links increase testing effort because each requires separate validation.
  • User roles and permission levels significantly affect authorization testing requirements.
  • Third-party integrations, cloud infrastructure, and internal services can expand the attack surface beyond the application itself.
  • Unauthenticated endpoints should be identified separately because they are often high-priority attack surfaces.
  • Bringing an endpoint and operation count to a scoping call helps vendors produce faster and more accurate pentest estimates.
1 REST API Endpoints
Count your REST API endpoints

Use the most accurate source available:

•OpenAPI / Swagger specification
•Route dump (rails routes, artisan route:list, manage.py show_urls)
•Proxy capture of application traffic
•Fallback: estimate features × 5
Path + HTTP method = 1 endpoint

GET /users and POST /users are two endpoints, not one.

2 GraphQL Operations
Count your GraphQL operations

Introspection query or schema file. Count every field under Query and every field under Mutation.

Report as: X queries + Y mutations = Z total

One GraphQL URL ≠ one endpoint. Operation count is what drives scope.

3 Effort Multipliers — document these before your call
List every authentication method

Password, SSO (Okta, Auth0), magic links, API keys, MFA — each has a distinct vulnerability profile requiring separate testing.

Count distinct user roles / permission levels

Admin, standard, read-only, unauthenticated. Authorization must be verified per role on every sensitive endpoint.

List all third-party integrations

Payment, CRM, analytics, communication tools — e.g. Stripe, Salesforce, HubSpot, Twilio.

List internal and cloud infrastructure dependencies

Internal microservices, S3 buckets, and cloud storage — each is a data boundary that may be internal or external.

Flag unauthenticated endpoints separately

Highest-priority attack surface. Testers focus here first.

4 Before the Scoping Call
Add REST endpoints + GraphQL operations for your base attack surface count

This single number is the most important thing you bring to the scoping call.

Note which counting method you used and flag any uncertainties

e.g. 'OpenAPI spec — may have dead routes' or 'Feature estimate × 5 — rough estimate, not verified against code.'

Scoping Method Reference
MethodAccuracyRisk
Domains / SubdomainsLowMisses API logic entirely
Features / User StoriesMediumInconsistent estimates
Pages / ScreensLowUndercounts SPA backends
Endpoints / Operations ✓HighMost reliable — recommended
Ready to scope your pentest?

Our consultants deliver a customized quote within 48 hours.

Book a Consultation →

softwaresecured.com

Ready to get in touch? Get started by booking a consultation now.

Book Consultation

Get security insights straight to your inbox

Continue your reading with these value-packed posts

Black arrow icon
Penetration Test Reports & ROI

How to Schedule a Penetration Test Without Disrupting Your Sprint Cycle

Kaycie Waldman
Kaycie Waldman
7 min read
June 5, 2026
15 Risks & Rewards of Pentesting in a Production Environment
Black arrow icon
API & Web Application Security Testing

15 Risks & Rewards of Pentesting in a Production Environment

Warren Moynihan
Warren Moynihan
14 min read
November 1, 2021
Social engineering cybersecurity awareness and defense
Black arrow icon
Penetration Testing Services

Worried Penetration Testing Will Derail Your Sprint Cycle?

Sherif Koussa
Sherif Koussa
12 min read
August 9, 2023

Helping companies identify, understand, and solve their security gaps so their teams can sleep better at night

Book a Consultation
Centralize pentest progress in one place
Canadian based, trusted globally
Actionable remediation support, not just findings
Clutch logo
Web, API, Mobile Security
Web App PentestingMobile App PentestingSecure Code Review
Infrastructure & Cloud Security
External Network PentestingInternal Network PentestingSecure Cloud Review
AI, IoT & Hardware Security
AI PentestingIoT PentestingHardware Pentesting
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
More Services
Pentesting as a ServiceSecure Code Training
Industries
Data and AIFinanceHealthcareSecuritySaaS
Compliance
GDPR PentestingHIPAA PentestingISO 27001 PentestingPCI DSS PentestingSOC 2 Pentesting
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
Comparisons
Software Secured vs Cobalt
Security & CompliancePrivacy PolicyTerms & Conditions
2026 ©SoftwareSecured