Find the flaws in your web application before someone else does.
I test your website or web app the way an attacker would, then hand you a clear report: what's broken, how serious it is, and exactly how to fix it. One person scopes the work, does the testing, and writes the findings.
Request a scoping callWhat I test for
Each area is explained in plain language first, then in technical detail for your IT team.
Broken authentication
Can someone get into an account that isn't theirs? Weak logins are the front door left unlocked.
Login and password-reset flows, session token handling and expiry, MFA bypass, credential stuffing and brute-force protections, account enumeration.
Access controls
Can one customer see another customer's data, or a regular user act like an admin?
Broken object-level authorization (IDOR), privilege escalation, horizontal and vertical access checks, role enforcement on every API endpoint, not just in the UI.
Business logic flaws
Ways to use your app “correctly” that still cost you money, like skipping a payment step or reusing a coupon.
Workflow and state manipulation, price and quantity tampering, race conditions, rate-limit and abuse cases that scanners can't find because they require understanding what your app is meant to do.
Injection
Can someone type something into a form that tricks your system into running commands or handing over data?
SQL and NoSQL injection, cross-site scripting (XSS), command injection, template injection, and unsafe handling of user input in parameters, headers, and JSON bodies.
Data exposure
Is private information showing up where it shouldn't, in the page, in an error message, or in a file anyone can open?
Sensitive data in API responses, verbose errors, exposed debug endpoints and backups, secrets in client-side code, missing transport and storage protections.
How I test
Hands-on, manual testing, so I find problems that depend on how your app really works.
Browser developer tools
I inspect what your app sends and stores in the browser: requests, cookies, local storage, and the front-end code. Anything visible there is visible to an attacker too.
Intercepting proxy
I route traffic through a proxy so I can pause, modify, and replay requests between the browser and your server. This is how I check whether the server enforces its rules or just trusts what the browser sends.
What working together looks like
- ScopeWe agree on what's in bounds, the testing window, and the rules of engagement in writing.
- TestI work through the five areas above against your live or staging application.
- ReportYou get an executive summary for leadership and detailed findings for your developers, each with severity, evidence, and a fix.
- QuestionsI walk your team through the results so nothing is left ambiguous.
Not sure what's in scope?
Tell me about your application and I'll tell you what's worth testing.
Get in touch