Web Application Security
OWASP-aligned testing for auth flaws, business logic bugs, injection, and broken access control. You get a prioritized report with proof-of-concept steps and clear fix guidance.
Get a QuoteProfessional web application, network, and cloud security assessments for startups and enterprises.
Manual and automated security testing for web apps, APIs, mobile, cloud, and AI/LLM systems. Get a clear report, remediation guidance, and a free retest when fixes are done.
Book directly for custom scopes and faster turnaround. Book on Fiverr if you prefer.
OWASP-aligned testing for auth flaws, business logic bugs, injection, and broken access control. You get a prioritized report with proof-of-concept steps and clear fix guidance.
Get a QuoteREST, GraphQL, and SOAP testing - auth bypass, IDOR, rate limiting gaps, and excessive data exposure. Ideal before launch or after a major API change.
Get a QuoteAndroid and iOS testing for insecure storage, API trust issues, certificate pinning gaps, and runtime protections. Static and dynamic analysis included.
Get a QuoteAWS, Azure, and GCP reviews for IAM misconfigs, public storage, overly permissive roles, and gaps against CIS benchmarks and cloud security best practices.
Get a QuotePrompt injection, tool abuse, agent hijacking, and OWASP LLM Top 10 testing for chatbots, RAG pipelines, and AI coding agents like Cursor and Claude.
Get a QuoteMulti-app programs, compliance-driven reviews, and retainer-based testing. Reach out for a tailored quote.
Get a QuoteStraightforward tiers - custom scopes available on request
All packages include a prioritized report, remediation guidance, and one retest round. Need something bespoke? Contact me.
One web application, OWASP Top 10 coverage, executive summary, and detailed report.
Get a QuoteREST or GraphQL review focused on auth, IDOR, rate limiting, and data exposure.
Get a QuoteWeb + API + mobile in one engagement, with one retest round after fixes.
Get a QuotePrompt injection, tool abuse, and agent hijacking tests for chatbots, RAG, and coding agents.
Get a QuoteComprehensive security testing approach
Before testing begins, we establish a clear scope together. Open communication sets a comfortable foundation and keeps the assessment focused on what matters to your business.
OSINT and reconnaissance help map your attack surface - domains, infrastructure, and dependencies - so risk is assessed accurately throughout the engagement.
Manual and automated testing across agreed targets. Controlled exploitation validates real impact while protecting production stability and sensitive data.
Findings are consolidated into an executive summary and a detailed technical report with severity ratings, reproduction steps, and remediation guidance.
We walk through fixes, verify closures with retests where needed, and deliver a remediation report showing the improved security posture of your application.
Recognized by Siemens CERT and other security programs for responsible disclosure.
Common questions before booking an assessment
Most web and API assessments run 5-10 business days once scope is agreed. Mobile and cloud reviews vary with app complexity and environment size. I share a timeline during scoping so you know what to expect before we start.
Every engagement includes an executive summary, detailed findings with severity ratings, proof-of-concept steps, and remediation guidance. Critical and high issues get extra attention so your team knows exactly what to fix first.
Yes. I work under NDA for most client engagements. Credentials, staging URLs, and reports stay confidential. Happy to use your standard NDA or provide one.
Yes. One retest round is included for validated findings once you have patched. You receive an updated report showing what is closed and what still needs work.
Automated scans surface known issues quickly but miss business logic, chained exploits, and context-specific flaws. Penetration testing combines manual testing, custom tooling, and real attack scenarios to find what scanners miss.
Both. I have tested 300+ applications across startups, scale-ups, and enterprise teams. Scope and pricing flex to match your stage - from a focused pre-launch review to a full product assessment.
I'm Piyush Kumawat, Staff Product Security Engineer and freelance penetration tester
Staff Product Security Engineer at Harness with a background in hands-on penetration testing. I have assessed 300+ web, mobile, and API applications across fintech, SaaS, and enterprise products.
Threat modeling, DevSecOps tooling, and cloud security reviews on AWS, Azure, GCP, and Alibaba Cloud. I focus on findings your team can actually fix - not checkbox compliance.
"Clear reports, practical remediation advice, and no hand-waving on severity." - the feedback I aim for on every engagement.
Ready to scope an assessment? Send a message and I will reply within 24 hours.