Web and Mobile Application Security Assessments
A structured security check of the specific website, customer portal or mobile app your business runs, walked through screen by screen and role by role. GullySystem runs it before a launch or once a concern has been raised.
What Gets Tested and Why It Matters
This assessment looks at the application itself — the screens, forms, logins and roles your customers, dealers or staff interact with every day — rather than the servers underneath it or the wider network. It is run by working through the real user journeys of your specific application, using an account for every role it defines, not by pointing a generic tool at the homepage.
Weak Points This Uncovers
- A logged-in student can edit a link and open another student's report card
- A discount code applied at checkout can be changed after it leaves the browser, before the server ever sees it
- A signup form has no limit on attempts, so a script can create thousands of fake accounts overnight
- A property-listing app stores the agent's login token in a spot another app on the same phone can read
What We Actually Do
Walk Through Every Role by Hand
Test accounts for each role — customer, staff, admin, vendor — are used to try things the interface does not obviously offer.
Check Payment and Checkout Paths
Amounts, discounts and order totals are followed from the screen to the server to see whether any of them can be altered along the way.
Review Uploads and Downloads
What can be uploaded, where it lands, and whether a document link works for someone who never logged in at all.
Examine What the Mobile Build Leaves Behind
Data left on the device after use, and whether traffic between the app and its server can be read or changed in transit.
Web vs Mobile: What Changes
- Web: cookies, browser storage, forms and how the page behaves when a request is replayed or altered
- Mobile: what is stored on the device itself, how the installed app package can be examined, and OS-level permissions the app requests
- Both: the same underlying question — can one user, role or device reach something that belongs to someone else
When to Run This Assessment
- Before a new customer-facing portal or app goes live
- After adding a payment feature, a new user role, or a major redesign
- After a user or partner reports behaviour that does not look right
- Ahead of an enterprise customer's security questionnaire that names your application specifically
Frequently asked questions
Does a simple website need this?
Usually not. A brochure site with no login, no customer accounts and no data collection carries little of this risk, and we will say so rather than sell an assessment you do not need. This is built for applications where people log in and see records that belong only to them.
What decides the cost of an assessment like this?
The number of distinct user roles the application defines, how many screens and flows those roles touch, whether payments are involved, and whether a mobile build is in scope alongside the web version. A simple two-role portal costs less to cover thoroughly than an app with a dozen permission levels.
What decides how long an application assessment takes?
Mostly how quickly test accounts for every role and, where one exists, access to a staging copy are made available. Testing against a live system with no staging environment usually needs to be scheduled around your business hours, which adds time rather than testing effort.
Does it matter who originally built the application?
No. We can assess an application built in-house, by another agency, or by a developer who is no longer reachable. Source code is not required for this kind of testing — it is done by working through the running application itself.
Who owns the report and the fixes that come out of it?
You do, in full. The findings, the evidence and any code changes made during remediation belong to you, and any credentials issued to us for the engagement are yours to revoke once it ends.
What do you need from us before starting?
A working account for every role the application supports, agreement on whether testing happens on a staging copy or a live system with limits, and one contact we can reach during the test window if something needs a quick decision.
Tell us what you need.
Send a short brief and one of our engineers will come back to you — usually the same day.
- No obligation
- We reply the same working day
- Your details stay private