Web Application Pentest
Deep, manual testing of your web app and its business logic — well past what any automated scan reaches.
- Authentication, authorization & IDOR
- Injection, SSRF, deserialization, RCE
- Business-logic & multi-tenant flaws
Manual, evidence-driven penetration testing for web apps, mobile (Android & iOS), APIs and networks — plus full red-team engagements. Real exploitation, a developer-ready report, and a free retest. No filler.
Every engagement is manual-first, scoped to your stack, and delivered with a developer-ready report. Freelance — it's me doing the testing, not a black-box scan.
Deep, manual testing of your web app and its business logic — well past what any automated scan reaches.
Static, dynamic and runtime testing of your mobile apps, aligned to OWASP MASVS.
REST, GraphQL and gRPC, mapped to the OWASP API Security Top 10.
External and internal network testing — find the path to impact before an attacker does.
Goal-based adversary simulation — phishing to domain admin, mapped to MITRE ATT&CK.
No black box. You know what's happening at every stage, and exactly what you'll get at the end.
Free call, rules of engagement, NDA & a fixed quote.
Map the attack surface, enumerate, threat-model.
Manual testing & chaining, with safe, real PoCs.
Findings, CVSS, business impact & clear fixes.
I re-verify your fixes — included, no extra cost.
Tell me a bit about your target and I'll come back within 48 hours with a fixed quote and timeline. The scoping call is always free.