Web application and API penetration testing
Manual, business-logic-aware testing against OWASP standards, including the API Security Top 10: authentication, authorisation (BOLA and BFLA), mass assignment, rate limiting and data exposure.
Manual security testing from a developer-turned-attacker. Twenty years of building software, used to find the flaws that automated scanners and generalist testers miss, and to explain them in a way your developers will act on.
Most clients come to us at one of a few points. Here is what we do at each.
Manual, business-logic-aware testing against OWASP standards, including the API Security Top 10: authentication, authorisation (BOLA and BFLA), mass assignment, rate limiting and data exposure.
New features, integrations, a migration or an inherited codebase. We focus on what changed, so you don't pay to retest what hasn't.
Assessment of LLM-powered applications, agents and MCP servers: prompt injection, insecure output handling, excessive agency, sensitive data leakage and weak tool permissions.
Practical, code-level training for your team, drawing on our Pluralsight courses on ASP.NET Core security, API security and C# authentication.
Most testers learn to break software. We spent two decades building it first.
Around 20 years of software development means we understand your architecture, your frameworks and the shortcuts that create vulnerabilities.
Every finding has reproduction steps, root cause and remediation guidance in terms of your stack, not a raw scanner dump.
Findings come from hands-on testing and judgement, with tooling in support. That means deeper coverage and fewer false positives.
Pen test reports are often judged on length. We write them to be acted on. Every finding includes:
"Testimonial text goes here."
Name, role, company
Our Pluralsight courses teach secure coding and offensive security with practical, code-level examples. We bring the same material and the same style to in-house team training.
Feedback:
"The real-world example using BURP are fantastic! The speaker is easy to understand also. Good work"
"I was able to acquire great knowledgeable from this course. It will surely help me in making my projects more secure."
"The instructor provides not just concepts, but real-world examples and resources to make the ideas presented much clearer."
"I've been subjected to many security training videos, and I think this was the most useful one yet...Excellent foundation course."
DevSec Forge is a penetration testing and application security consultancy based in northeast England. Our founder, Gavin Johnson-Lynn, spent around 20 years as a software developer before moving into offensive security, including a spell as security lead on a payments platform at a large UK financial services company.
That background is the point. We know how software gets built and where the pressure to ship creates weak spots, so we find the issues that matter and explain them in a way developers accept and fix. We work with UK and remote clients.
We also teach and contribute to the community: our Pluralsight courses cover ASP.NET Core security, API security and C# authentication, and we contribute to the OWASP Top 10 and OWASP API Security Top 10.
Tell us what you're building and what worries you about it. We'll suggest a sensible scope.