API & BACKEND DEVELOPMENT.

REST and GraphQL APIs, integrations and event-driven backends that are documented, rate-limited and tested for the authorisation flaws in the OWASP API Top 10. The backend behind our web and mobile apps — and yours.

► Get a Fixed-Price Estimate Pricing & FAQ
Overview

API & Backend Development by Evosec Consulting

Every product we build runs on an API, and most of the critical findings in our penetration tests live in APIs too: broken object-level authorisation, mass assignment, unbounded queries, leaky error messages. Evosec's API development practice exists to build backends that don't have those problems.

We build on Laravel and Node.js, document with OpenAPI, ship with contract tests, and integrate with the third-party systems that make products real: Stripe, Adyen, Twilio, Onfido, Salesforce, SAP, and the French and Tunisian banking gateways.

What's Included
▌ 01

REST & GraphQL APIs

Versioned, paginated, documented with OpenAPI / GraphQL schema, backed by contract tests.

▌ 02

Third-party integrations

Payments, KYC/AML, e-signature, ERP/CRM, shipping, messaging — with retries, idempotency and webhooks done right.

▌ 03

Mobile backends

Token auth with refresh rotation, push, offline sync, media handling and rate limiting for iOS/Android clients.

▌ 04

Event-driven systems

Queues, workers, schedulers and event streams (Redis, SQS, Kafka) for workloads that shouldn't block a request.

▌ 05

Data & performance

PostgreSQL schema design, indexing, caching strategies and observability so you know why something is slow.

▌ 06

API security

OWASP API Top 10 testing before launch, auth/authz review, secrets management, WAF and abuse protection.

Stack & Tools
LaravelNode.js / NestJSPostgreSQLRedisOpenAPIGraphQLAWS (SQS, Lambda)Docker
Secure by Design
  • Threat model written during discovery
  • Static analysis & dependency audit on every commit
  • Manual penetration test before every release
  • Findings fixed by the engineers who wrote the code
  • GDPR / RGPD privacy-by-design review
  • Fixed-price milestones · weekly demos · staging from day one
FAQ
REST or GraphQL?

REST for most public APIs and integrations; GraphQL when many client types need flexible queries against a rich data graph. We've shipped both and will recommend based on your consumers.

Can you integrate with our legacy ERP?

Yes — SAP, Sage, Odoo, Dynamics and bespoke systems via APIs, files or database sync, with reconciliation and monitoring.

How do you test API security?

Automated scanning in CI plus a manual test against the OWASP API Security Top 10 by our penetration testers before every major release.

Do you build the mobile app too?

Yes — most of our API projects ship alongside a React Native or Flutter app built by the same team.

Related
Mobile Backend & APIs → Laravel Development → SaaS & MVP Development →
► Start a Project All Web Development →