Object Authorization
BOLA and IDOR testing across records, files, accounts, tenants, transactions, and other directly addressable objects.
API Security
TruSec evaluates REST, GraphQL, mobile backends, and service integrations to identify object-level authorization failures, excessive data exposure, workflow abuse, and other API-specific attack paths.
Service Overview
APIs frequently expose direct access to business objects, administrative actions, and sensitive data. Strong authentication alone does not prevent a user from requesting another user’s records, manipulating identifiers, invoking hidden functions, or automating workflows in unintended ways.
TruSec tests documented and discovered endpoints using the approved credentials, roles, tokens, schemas, and client workflows. The assessment considers how endpoints interact, whether authorization is enforced consistently, and whether an attacker can combine normal API functions into a harmful outcome.
Assessment Coverage
Coverage is shaped by endpoint count, authentication methods, roles, documentation quality, data sensitivity, and business functions.
BOLA and IDOR testing across records, files, accounts, tenants, transactions, and other directly addressable objects.
Role and privilege boundaries, administrative endpoints, hidden methods, mass assignment, and vertical access-control failures.
Token issuance, validation, expiration, revocation, scopes, JWT handling, API keys, secrets, and alternate login paths.
Injection, parser behavior, deserialization, file handling, content types, parameter pollution, and server-side request risks.
Brute force, enumeration, automation, pagination abuse, expensive requests, resource consumption, and anti-automation controls.
Workflow manipulation, sequence bypass, excessive data exposure, unsafe defaults, error leakage, and unintended field access.
How the Engagement Works
Confirm hosts, versions, endpoint count, roles, authentication, documentation, and excluded actions.
Inventory endpoints, methods, objects, parameters, schemas, and expected authorization behavior.
Manipulate objects, roles, inputs, sequences, and rate controls to validate exploitable conditions.
Document endpoint-specific evidence, affected roles or objects, impact, remediation, and retest status.
Deliverables
The report connects technical behavior to the affected business object, user role, workflow, and potential impact.
Scope changes caused by undocumented endpoints or material differences in the provided API inventory are discussed before additional testing is performed.
Common Questions
Useful inputs include API hosts and versions, approximate endpoint count, documentation or collections, authentication method, user roles, test data needs, and high-risk business workflows.
Yes. Testing can evaluate schema exposure, object and field authorization, batching, query depth, mutations, introspection, error handling, and business-logic abuse.
Yes. The API can be assessed directly and in the context of the mobile client to identify hidden endpoints, weak trust assumptions, token handling, and inconsistent authorization.
Rate limiting and automation resistance can be evaluated within safe request thresholds and the approved rules of engagement. High-volume denial-of-service testing is not performed unless specifically authorized.
Related Services
Share the API hosts, approximate endpoint count, documentation, authentication methods, user roles, and the workflows or data that carry the greatest risk.