I will audit your API for broken access control and authorization bugs
Security Researcher and Web Security Tester
Informazioni su questo servizio
Your API might be leaking other users' data right now and standard scanners won't catch it.
I specialize in API authorization testing: IDOR/BOLA, broken object-level access control, mass assignment, and business logic flaws the vulnerability classes that automated tools consistently miss because they require understanding how your app's roles and ownership rules should work, then breaking them.
What you get:
- Manual, hypothesis-driven testing of your API endpoints (REST/GraphQL)
- Multi-account testing across roles/tenants to catch horizontal & vertical privilege escalation
- A clear report: vulnerability, reproduction steps, business impact, and remediation guidance
- No generic scanner output every finding is manually verified
Good fit for: SaaS platforms, fintech, marketplaces, or any product with user-owned resources and role-based access.
I've found and reported real-world IDOR/BOLA and business logic bugs across multiple bug bounty programs (HackerOne, Bugcrowd, Intigriti). I bring that same hypothesis-first methodology to your assessment.
