Penetration Test — REST & GraphQL API
OWASP API Top 10 manual test. Up to 50 endpoints, REST or GraphQL. Auth flow review. Retest included. SOC 2 / ISO 27001 ready. €539 fixed. 7-day delivery.
Penetration Test — REST & GraphQL API by Optimum Web is a fixed-price compliance service covering OWASP API Top 10 + GDPR Art. 32 + ISO 27001 A.8.28 + SOC 2 CC7.1 + PCI DSS Req. 6/11. It costs €539 with 7 business days delivery by senior security engineers. OWASP API Top 10 coverage report with PoC for each finding. 14-day warranty included.
Covers: OWASP API Top 10 + GDPR Art. 32 + ISO 27001 A.8.28 + SOC 2 CC7.1 + PCI DSS Req. 6/11
"Senior engineers who actually deliver what they promise. Rare."
Thomas K., IT Manager · Austria
Secured by PayPal · 256-bit SSL encryption
This Service Covers
What You Get
Who Needs This
- SaaS companies serving EU customers via API
- Fintech, healthtech, and B2B platforms with mobile or partner integrations
- Organisations that recently shipped a new API or major version
- Teams whose last API security review is more than 12 months old
- Businesses preparing for SOC 2 or ISO 27001 audit
ONGOING COMPLIANCE
Don't Want to Think About Compliance Every Quarter?
Compliance-as-a-Service: €729/month. We handle reviews, scans, documentation, security questionnaires. Your outsourced compliance officer.
Start CaaS — €729/monthReady to Start?
€539 · 7 business days · 14-day warranty
Secured by PayPal · 256-bit SSL encryption
Want ongoing compliance? Compliance-as-a-Service — €729/month
Learn moreWhat Our Clients Say
"Senior engineers who actually deliver what they promise. Fixed price, fixed timeline, thorough documentation. Rare combination."
"Worked with 4 agencies before finding Optimum Web. First team that delivered exactly what the scope said, on time."
"The 14-day warranty is real. Had a small follow-up question and it was handled same day, no extra charge."
Frequently Asked Questions
REST or GraphQL — both?+
How many endpoints in scope?+
Do you test production or staging?+
What do you need from us to start?+
Can we get a retest after we fix findings?+
Will this satisfy our SOC 2 auditor?+
Also Relevant
Penetration Test — External Infrastructure & Cloud
€699 · 8 business daysPenetration Test — Internal Network & Active Directory
€729 · 10 business daysPenetration Test — Mobile Application (iOS or Android)
€729 · 10 business daysPenetration Test — Web Application
€539 · 7–10 business daysSecured by PayPal · 256-bit SSL encryption
