
AI-driven web application security testing for a technology company
Client need
An external assessment before expanding to business customers
A Finnish technology company develops an agentic AI-based service and was expanding it to business customers. The company wanted an external assessment of its web application security and a clear picture of the vulnerabilities its development team should fix.
The assessment covered the web application, its APIs and the relevant source code, with the focus on practical application security risks such as those in the OWASP Top 10. Fraktal ran the engagement with its AI-driven security testing harness, with the goal of findings the client's development team could fix directly.
We delivered
AI-driven assessment of the application, APIs and source code
Fraktal performed an AI-driven security assessment of the client's web application, APIs and relevant source code. AI agents analyzed the application, planned and executed security tests, investigated and validated potential vulnerabilities, and wrote up each finding with technical evidence and a recommended fix.
Experts supervising the harness
Fraktal's security experts configured and supervised the harness throughout. They monitored testing quality and scope, sampled results, watched for environmental or technical issues that could interfere with testing, and adjusted the harness when needed.
Report and walkthrough
The client received a security assessment report with the identified findings, the evidence behind each one and the recommended fixes, followed by a walkthrough of the results.
Our approach
Technical walkthrough and harness configuration
We started with a technical walkthrough of the application to understand it and configure the testing harness for the target. The AI agents then carried out the web application security testing workflow from investigation through validation and reporting.
A harness developed across engagements
Fraktal develops the harness continuously by using it across different web applications, technology stacks and customer environments. This shows us where agentic testing works well and where automation that looks successful can still miss relevant vulnerabilities.
Repeatable once configured
Once configured, the testing is repeatable. That makes the approach useful for applications that change often and for increasingly automated software development workflows.
Why this matters
Findings the development team can fix
The assessment identified multiple security findings and gave the client's development team remediation guidance for each.
Assessments that keep pace with the application
Automating the testing, validation and reporting workflow makes security assessments easier to repeat as the application evolves. Findings can increasingly flow into automated development workflows, where they are investigated, fixed and retested as part of the development cycle.
An excellent supplement to human-led assessment
Agentic AI testing is an excellent supplement to human-led assessment. It handles the repeatable parts of a web application test quickly and as often as the application changes, and Fraktal's consultants stay on the parts that need human judgment. As AI models and the harness improve, we expect the range and depth of testing that can be automated reliably to keep growing.