About apipentest.net
apipentest.net explains what a manual API penetration test is, how it is scoped and priced, what the report should contain, and which regulations expect one. This page says who is behind that advice and how it is written.
Who publishes this site
apipentest.net is published by SEQ SIA (registration No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq. OffSeq is an offensive-security company: penetration testing, security assessments and continuous threat monitoring. Contact: support@offseq.com.
This is a vendor-run resource. It is not a government body, a standards organization or an independent publication, and it does not present itself as one.
Who writes the content
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than a byline. Every page lists its sources so a reader can check the basis for the guidance instead of taking it on trust.
How the content is made
- Category names and definitions for the OWASP API Security Top 10 are quoted from the OWASP Foundation’s own 2023 edition, which is published under Creative Commons Attribution-ShareAlike 4.0.
- Regulatory obligations are quoted from the consolidated text on EUR-Lex, with the article number, so you can read the clause around the quotation.
- Where a standard’s text is behind a licence acceptance, as PCI DSS is, we summarize the requirement and say plainly that it is a summary rather than a quotation.
- Breach descriptions come from the original disclosure, regulator statement or filing, not from secondary coverage of it. Figures we cannot trace to a primary or first-hand source are left out, even when they are widely repeated.
- Price and effort figures are other companies’ published numbers, attributed by name and date. They are benchmarks for reading a quotation, not our price list.
- We describe what a test covers and how to buy one. We do not publish exploit code or steps that make attacking somebody else’s API easier.
- The “Updated” date moves only when the text actually changes; an automated content-hash ledger reverts unearned date bumps.
- Everything is readable without an account, a cookie banner or an email address.
The interactive tools
The scope estimator and the OWASP self-check run entirely in your browser. Your selections are not transmitted, not stored in local storage and not added to any outbound link. The estimator multiplies published effort bands by published day rates; it is a planning aid, and its own output says so.
Conflict of interest, stated plainly
The company that publishes this site sells API penetration testing. That is a direct commercial interest in you concluding that you need one, and you should read every recommendation here with that in mind.
- Links to OffSeq services are our own links, not an independent recommendation. Footer links to them carry
rel="nofollow sponsored". - No vendor pays to be mentioned here. There is no sponsored content, no advertising and no affiliate links.
- The competitor price lists quoted on this site are quoted accurately, including where they are cheaper than we are.
- Most of what this site teaches can be acted on without hiring anyone: the OWASP list, the ASVS requirements and the WSTG API chapter are all free.
What this site is not
It is not a scanner, a certification scheme or a substitute for reading the standard that applies to you. Scoping guidance is generic; the risk that matters is specific to the data behind your API.
Corrections
If something here is wrong, out of date or unfairly characterized, write to support@offseq.com. We correct substantive errors and move the update date visibly rather than quietly.