Authentication
Tokens, keys, expiry, renewal, revocation and resistance to abuse.
Penetration testing for REST and GraphQL APIs, focused on authentication, authorization, data and object exposure, and business rules.

The assessment looks at how endpoints, objects, identities and integrations behave when they receive calls outside the expected flow.
Public or partner APIs
Mobile apps and decoupled frontends
Service-to-service integrations
Migration or launch of a new version
We use documentation, collections and credentials when available to go deeper.
Tokens, keys, expiry, renewal, revocation and resistance to abuse.
Improper access to records, resources or actions that belong to other users.
Excessive fields, sensitive information and responses that reveal internal detail.
Limits, automation, operation sequences and exploitable business rules.
From technical alignment to delivery, the work has to leave context, evidence and next steps visible to everyone involved.




Documentation speeds the work up, but endpoints are also correlated from the application and the infrastructure.
We document assets, access, limits, execution window and owners before any activity starts.
Vorvex specialists carry out the work, with Apex supporting reconnaissance, correlation and evidence handling.
Findings are analyzed for exploitability, technical impact and consequence for the business.
We deliver reproducible evidence and recommendations and, when contracted, validate the fixes you applied.

The evidence states the endpoint, identity, request, response and observed impact.
Exposure summary, priority impacts and next steps to support decisions and investment.
Technical detail, context, reproduction steps and practical remediation guidance.
Scope, period, methodology and finding status documented for audit and accountability.
If your question isn't here, talk to the team directly.
Ask on WhatsAppYes. Coverage is defined according to the technology, authentication, documentation and business flows available.
No, but documentation or collections increase coverage and cut the time spent discovering endpoints.
The backend and the APIs the app uses can be included. Analysis of the mobile binary has to be described separately in the scope.
Share the type of API, the documentation you have and how many access roles exist.
Ready to assess your company's risk?