API security

Your APIs Are the Most Direct Path to Your Data.

APIs expose business logic and data with far less UI in the way. Nuclisafe tests REST, GraphQL and internal service APIs for the authorization and object-level flaws that dominate real-world API breaches.

What we test

Testing coverage across the attack surface

Coverage is tailored to your application. The areas below are assessed where applicable to the agreed scope.

AuthenticationAuthorizationBOLA / IDORBroken Object Property Level AuthorizationJWT SecurityOAuth SecurityRate LimitingInput ValidationInjectionSensitive Data ExposureMass AssignmentBusiness LogicAPI MisconfigurationGraphQL SecurityEndpoint Discovery

Common weaknesses

Issues we frequently look for

BOLA / IDOR

Object identifiers that can be swapped to read or modify another tenant's or user's data.

Broken Property Level Authorization

Endpoints returning or accepting fields a caller should never see or set.

JWT & Token Weaknesses

Weak signing, algorithm confusion, missing expiry validation and unsafe token storage or scope.

Mass Assignment

Unfiltered request bodies letting attackers change roles, prices or internal flags.

Missing Rate Limiting

Unthrottled endpoints enabling enumeration, brute force, scraping and cost abuse.

GraphQL Exposure

Introspection, deeply nested queries, batching abuse and resolver-level authorization gaps.

How we test

A manual-first testing approach

  • Endpoint discovery from documentation, specifications, client traffic and brute-force enumeration.
  • Cross-role and cross-tenant matrix testing on every sensitive endpoint in scope.
  • Token and session analysis covering JWT, OAuth flows, refresh handling and scope enforcement.
  • Schema and property-level review for over-exposure and mass assignment.
  • Manual business logic abuse against transactional and workflow endpoints.

Aligned frameworks

OWASP API Security Top 10OWASP API Security Testing GuideNIST SP 800-204

Assessments are mapped to these industry frameworks and testing methodologies. This does not imply certification by, or partnership with, any of these organisations.

Example tools

Burp SuitePostmanInsomniaOWASP ZAPKiterunner42CrunchAPIsec

Illustrative only — tooling is selected per engagement and is not a guarantee of full coverage. Manual testing remains central to every assessment.

Deliverables

What you receive

Executive Summary

Business-level view of risk posture, key themes and priorities for leadership and stakeholders.

Technical Report

Detailed findings with affected endpoints, reproduction steps, evidence and references.

Proof of Concept

Validated demonstration of exploitability within the authorized scope, so nothing is theoretical.

Risk Rating

Severity based on impact and likelihood, supporting prioritization and remediation planning.

Remediation Guidance

Specific, actionable fix recommendations written for the developers who will implement them.

Retest Report

Post-fix verification confirming which findings are closed and which need further work.

Ready to start scoping?

Every assessment is scoped according to application complexity, attack surface and testing requirements.