Skip to content
Deependra Vishwakarma

Security and compliance engineering · fixed-price first step

Security audit and penetration test

An attacker's view of your application and infrastructure, and a fix list you can act on.

Manual and automated testing of your web application and its infrastructure against the OWASP Top 10 and beyond: authentication and authorization, injection, server-side request forgery, business-logic flaws, secrets and server configuration. I completed the Google Cybersecurity Specialization.

Timeline
Agreed per project after scoping
Price
Fixed price per scope
Engagement
Fixed-price

Is it a fit?

For

  • SaaS companies facing their first enterprise security questionnaire
  • Fintech and health products handling sensitive personal data
  • Teams preparing for SOC 2 or ISO 27001 who want the technical gaps found first

Not for

  • Formal certification audits: SOC 2 and ISO 27001 need an accredited auditor, and I help you get ready for one

What you get

  • A scoped test plan agreed in writing, with rules of engagement
  • Findings rated by severity, each with proof of concept and a fix
  • An infrastructure review: IAM, network rules, TLS, headers and secrets
  • A retest after your fixes, confirming what's closed
  • An executive summary for customers and investors

How it runs

  1. 01

    Scope

    Agree targets, accounts, time windows and what's out of bounds, in writing.

  2. 02

    Test

    Automated scanning for breadth, then manual testing where the real risks usually hide: access control and business logic.

  3. 03

    Report

    Findings with severity, evidence and fixes, walked through with your team.

  4. 04

    Retest

    After your fixes, I confirm what's closed and update the report.

Typical stack: Burp Suite · OWASP ZAP · Nmap · sqlmap · Semgrep · Trivy · Wazuh

Questions

Will testing disrupt production?

Testing runs against staging where possible. Where it must touch production, we agree time windows and limits in advance, and destructive tests are never run there.

What does a web application audit cover?

Authentication, session handling and authorization; injection of every kind; server-side request forgery; file handling; secrets; business-logic abuse; and the server and cloud configuration around the app.

Do you offer ongoing monitoring?

Yes. I can set up intrusion detection and log alerting, and review them on a monthly retainer.

Tell me about your project.

A short brief is enough to start. I’ll reply with questions, a suggested first step and when I could begin.