Automated vulnerability scanners can identify potential weaknesses. Penetration testing goes further by having a security professional manually test whether those weaknesses can actually be exploited and whether an attacker can use them to gain unauthorized access or sensitive information. Compliance+ Security performs manual penetration testing of web applications and APIs, with a focus on authentication, authorization, session management, business logic, data exposure and other vulnerabilities that automated scanning can miss. We will review your web site and web server configurations for vulnerabilities and work with your team to resolve them. In addition, we will perform manual penetration testing with the intent of finding vulnerabilities. Some of the key areas we will review are listed below. Based on our assessment, we will develop a remediation plan. Not all vulnerabilities should to be treated the same. Some will need to be addressed immediately while others may be addressed later. We will then work with you and your web team through the process of remediation.