Skip to content
← Learn

Web/API pentesting

Pentest preparation: checklist and multi-tenant matrix

Prepare accounts, roles, environments and rules of engagement. A synthetic matrix for discussing authorization without sharing secrets.

Before the scoping meeting Prepare a description of assets, owners, users, integrations and objectives. Confirm ownership or testing authorization. Record exclusions and operational constraints. Do not send credentials through the contact form: access exchange is arranged later through an appropriate channel.

Synthetic authorization matrix Example: member A → document A: allowed; member A → document B: denied; administrator A → document B: denied; member A → member management: denied; administrator A → member management A: allowed. A and B are fictional organizations. For each row record identity, resource, operation, expected outcome and evidence. Adapt permissions to your product: this is not a universal policy.

Readiness checklist Test accounts for each role and tenant; synthetic data; API documentation; authorized integrations; identified version and environment; emergency contact; agreed windows; data restoration capability; evidence channel; stop conditions. Declare missing accounts: never substitute a real customer’s credentials.

Closure and retesting Assign internal owners for reviewing findings and fixes. For retesting, record the fixed version, change applied, original cases and relevant variants. Outcomes may be fixed, partially fixed, still present or not verifiable because of a limitation. See a complete example.

Straight answers

How do I request a proposal?

Share the application type, roles and objective through the contact form. Do not send credentials or customer data.

Does a pentest guarantee security?

No. It evaluates an agreed scope and version within a testing window. Limitations and residual risk remain.

What is agreed before testing?

Assets, permissions, environments, exclusions, communication, deliverables and retest terms.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn