Web, API and AI security testing

Penetration testing your developers can act on

Manual security testing from a developer-turned-attacker. Twenty years of building software, used to find the flaws that automated scanners and generalist testers miss, and to explain them in a way your developers will act on.

  • 20 yearsbuilding software
  • Security lead in regulated payments software
  • OWASP contributorTop 10 and API Security Top 10
  • CSSLPcertified
  • Pluralsight authorASP.NET Core and API security
  • Event speaker
Services

Testing for the moments that matter

Most clients come to us at one of a few points. Here is what we do at each.

Before you launch

Web application and API penetration testing

Manual, business-logic-aware testing against OWASP standards, including the API Security Top 10: authentication, authorisation (BOLA and BFLA), mass assignment, rate limiting and data exposure.

After major changes

Targeted testing of what changed

New features, integrations, a migration or an inherited codebase. We focus on what changed, so you don't pay to retest what hasn't.

When you build with AINew

AI and LLM security testing

Assessment of LLM-powered applications, agents and MCP servers: prompt injection, insecure output handling, excessive agency, sensitive data leakage and weak tool permissions.

For your developers

Developer security training

Practical, code-level training for your team, drawing on our Pluralsight courses on ASP.NET Core security, API security and C# authentication.

Approach

Why teams hire DevSec Forge

Most testers learn to break software. We spent two decades building it first.

We read code like your team does

Around 20 years of software development means we understand your architecture, your frameworks and the shortcuts that create vulnerabilities.

Reports developers can use

Every finding has reproduction steps, root cause and remediation guidance in terms of your stack, not a raw scanner dump.

Manual first

Findings come from hands-on testing and judgement, with tooling in support. That means deeper coverage and fewer false positives.

How an engagement works

  1. Scoping callYour goals, systems and constraints.
  2. Quote and rulesFixed-scope quote and a written agreement on what is in and out of bounds.
  3. TestingCritical findings flagged to you immediately.
  4. Report and walkthroughA session to walk through findings with your developers.
  5. RetestFree retest of fixes within an agreed window.
What you get

Findings your developers can fix

Pen test reports are often judged on length. We write them to be acted on. Every finding includes:

  • Severity and business impact in plain terms
  • Step-by-step reproduction, so your team can see it for themselves
  • The root cause, not just the symptom
  • A specific fix, with code where it helps
Training

Security training developers actually finish

Our Pluralsight courses teach secure coding and offensive security with practical, code-level examples. We bring the same material and the same style to in-house team training.

Feedback:

"The real-world example using BURP are fantastic! The speaker is easy to understand also. Good work"
"I was able to acquire great knowledgeable from this course. It will surely help me in making my projects more secure."
"The instructor provides not just concepts, but real-world examples and resources to make the ideas presented much clearer."
"I've been subjected to many security training videos, and I think this was the most useful one yet...Excellent foundation course."
View our Pluralsight courses
About

A developer's view of security

DevSec Forge is a penetration testing and application security consultancy based in northeast England. Our founder, Gavin Johnson-Lynn, spent around 20 years as a software developer before moving into offensive security, including a spell as security lead on a payments platform at a large UK financial services company.

That background is the point. We know how software gets built and where the pressure to ship creates weak spots, so we find the issues that matter and explain them in a way developers accept and fix. We work with UK and remote clients.

We also teach and contribute to the community: our Pluralsight courses cover ASP.NET Core security, API security and C# authentication, and we contribute to the OWASP Top 10 and OWASP API Security Top 10.

Contact

Tell us what you're building

Tell us what you're building and what worries you about it. We'll suggest a sensible scope.