Web/API pentesting
Web and API pentesting in Uruguay
Human-led Web/API pentesting from Montevideo. Scope, evidence and readiness for Uruguayan businesses.
From Montevideo, with defined scope
REKON operates from Montevideo, Uruguay. We evaluate web applications and APIs under written authorization and agreed scope. For customer portals, fintech products and SaaS, we start with access decisions and workflows that can affect data or operations. Meet the team and request a proposal.
What to define before commissioning
Identify the application, API, roles and environment. If you work with a software vendor, agree on who authorizes testing and who fixes findings. For assessments tied to procurement or a customer requirement, share evidence requirements without confidential details. Schedule, currency, payment and retesting are confirmed in the proposal.
Security and regulatory context
We do not present a pentest as certification or an identical obligation for every business. Decree 66/025 establishes a cybersecurity framework whose applicability must be assessed for each entity. Sector and contractual requirements need specific review. A report documents testing and limitations; it does not establish overall compliance.
Evidence before commissioning
Review the synthetic report, cost drivers and Web/API scope. A non-sensitive product description and objective are enough to start.
Straight answers
What is agreed before testing?
- Assets, roles, permissions, limitations, window, deliverables and retest terms.
Is this a certification?
- No. The report describes evidence within scope, not overall compliance or guaranteed security.
How do I start?
- Share non-sensitive context through the form. Do not send credentials.
Time to test your doors?
Tell us what needs validating. We answer with proposed scope, not a brochure.