I will pentest your website with a professional penetration testing report
Security Consultant at Big Four, Penetration Tester, 6 CVEs
Niveau 2
Répond à des critères de performance élevés et a fait ses preuves en matière de satisfaction clients.
À propos de ce service
Is your web app secure, or just not hacked yet? Manual vulnerability assessment and penetration testing (VAPT) for startups and small businesses, not a scanner export.
WHAT IS INCLUDED
OWASP Top 10 and SANS/CWE Top 25, tested by hand: authentication, access control (IDOR), injection, SSRF, uploads, misconfigurations
Business-logic tests built for your business type (SaaS, fintech, e-commerce, healthcare) from 100+ engagements
Every finding verified: no false positives
Executive summary + technical report: CVSS severity, reproduction steps, screenshots, fixes
Live client portal access: view findings instantly, invite developers and assign fixes, request retests, and download reports in multiple formats all in one place.
WHY ME
Security consultant at a Big Four consulting firm, testing banks and telecom operators
500+ critical vulnerabilities found across 100+ applications, six CVEs
100% on-time delivery record
HOW WE WORK
1. Share your URL, scope and test accounts (you must own the app)
2. I confirm scope and start within 24 hours; Instant email notifications for critical findings
3. Report on time: plain English plus developer detail
4. You fix, I retest for free
Mon portfolio
FAQ
Do you need my source code or credentials?
No source code for a black-box test. For Standard and Premium, create one test account per role you want tested. Credentials are shared only on the order page and deleted after delivery. NDA on request.
Is this an automated scan or a manual test?
Both, but the value is manual. Tools cover the basics; most of my time goes into authentication, access control and business logic by hand, and every finding is verified before it enters the report.
What does the report contain?
Executive summary, scope and methodology, a findings table by CVSS severity, and for each finding: description, impact, reproduction steps with screenshots or requests, and a specific fix. White-label available.
Can I see a sample report?
Yes. A redacted sample is attached to this gig as a PDF. Message me if you want a sample for a specific technology.
Will testing affect my live site?
Testing is non-destructive: no denial of service, no data deletion, no spam to real users. I recommend a staging environment when available; on production I keep automated scanning light.
Do you retest after we fix the issues?
Standard and Premium include one retest of all findings within 30 days of delivery, with an updated report you can share with customers or auditors. Basic can add a retest as an extra.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment finds and lists weaknesses, mostly with tools. A penetration test proves which ones an attacker can actually exploit and how far they get. You get both here: every finding is verified and exploited safely, then ranked.
Can you test a site I do not own?
Only with written authorization from the owner, confirmed in the order requirements. Without it the order is cancelled, no exceptions.
Why are you more expensive than the US$20 gigs?
Those gigs deliver a scanner export. This test is done by a consultant who tests banks and telecom operators for a living, and the report is the same standard those clients receive.
What is Vexil (Client Portal)?
Vexil is my private client website. With Standard or Premium you get a login: each vulnerability I confirm appears there the same day with proof and a fix, your developer marks it fixed and asks me to retest, and you download the report as PDF, Word or Excel. The PDF is also delivered here.

