AI-driven web application security testing for a technology company

AI-driven web application security testing for a technology company

Client need

An external assessment before expanding to business customers

A Finnish technology company develops an agentic AI-based service and was expanding it to business customers. The company wanted an external assessment of its web application security and a clear picture of the vulnerabilities its development team should fix.

The assessment covered the web application, its APIs and the relevant source code, with the focus on practical application security risks such as those in the OWASP Top 10. Fraktal ran the engagement with its AI-driven security testing harness, with the goal of findings the client's development team could fix directly.

We delivered

AI-driven assessment of the application, APIs and source code

Fraktal performed an AI-driven security assessment of the client's web application, APIs and relevant source code. AI agents analyzed the application, planned and executed security tests, investigated and validated potential vulnerabilities, and wrote up each finding with technical evidence and a recommended fix.

Experts supervising the harness

Fraktal's security experts configured and supervised the harness throughout. They monitored testing quality and scope, sampled results, watched for environmental or technical issues that could interfere with testing, and adjusted the harness when needed.

Report and walkthrough

The client received a security assessment report with the identified findings, the evidence behind each one and the recommended fixes, followed by a walkthrough of the results.

Our approach

Technical walkthrough and harness configuration

We started with a technical walkthrough of the application to understand it and configure the testing harness for the target. The AI agents then carried out the web application security testing workflow from investigation through validation and reporting.

A harness developed across engagements

Fraktal develops the harness continuously by using it across different web applications, technology stacks and customer environments. This shows us where agentic testing works well and where automation that looks successful can still miss relevant vulnerabilities.

Repeatable once configured

Once configured, the testing is repeatable. That makes the approach useful for applications that change often and for increasingly automated software development workflows.

Why this matters

Findings the development team can fix

The assessment identified multiple security findings and gave the client's development team remediation guidance for each.

Assessments that keep pace with the application

Automating the testing, validation and reporting workflow makes security assessments easier to repeat as the application evolves. Findings can increasingly flow into automated development workflows, where they are investigated, fixed and retested as part of the development cycle.

An excellent supplement to human-led assessment

Agentic AI testing is an excellent supplement to human-led assessment. It handles the repeatable parts of a web application test quickly and as often as the application changes, and Fraktal's consultants stay on the parts that need human judgment. As AI models and the harness improve, we expect the range and depth of testing that can be automated reliably to keep growing.