Skip to content
Jalwan
Freelance Web Application Penetration Tester

Find the vulnerabilities before attackers do

I'm Jalwan — a freelance penetration tester who manually breaks web apps, APIs, and SaaS platforms so your team can fix what matters. Real exploits, clear reports, no automated-scan noise.

  • Manual, human-led testing
  • Developer-ready reports
  • Free fix verification retest
Security engagements delivered
30+Security engagements delivered
Serious issues found & reported
100+Serious issues found & reported
Years in application security
4Years in application security
Average report turnaround
10 daysAverage report turnaround
How it works

A transparent engagement, start to finish

  1. 01

    Plan & agree scope

    We agree exactly what gets tested, with a fixed price and timeline up front. I'll sign an NDA if you need one.

  2. 02

    Explore your app

    I go through your whole app the way an attacker would — every page, login, and user role.

  3. 03

    Test by hand

    I try to break in for real: stealing other users' data, bypassing logins, and abusing your app's logic. Every issue is proven, not guessed.

  4. 04

    Report & walk you through it

    You get a clear report ranked by risk, plus a call to explain what matters most and answer your team's questions.

  5. 05

    Help you fix & re-check

    I stay available while you fix things, then re-test every issue to confirm it's actually closed.

Deliverables

Reports your engineers will actually use

No 200-page tool printout — clear enough for you to understand, precise enough for your developers to fix.

Executive summary

A plain-language read on your risk posture that stakeholders and customers can follow.

Technical findings

Every issue with its severity, where it is, and clear steps to reproduce it — so your developers can act fast.

Remediation guidance

Prioritized fixes written for developers — not generic checklist advice.

Retest & attestation

Verification of every fix, plus an attestation letter for auditors and vendor reviews.

security-assessment-report.pdf
CRITICALCVSS 9.1
JAL-001

Broken Access Control — IDOR on /api/v1/invoices

GET /api/v1/invoices/1043
200 OK — returns another tenant's invoice
ImpactReproductionRemediationRetest ✓
Client feedback

Real results, real words

What teams say after an engagement — clear reports, honest severity, and fixes they could actually ship.

Jalwan conducted a detailed security assessment of our platform and identified several important issues we needed to address. The report was clear, well documented and included practical recommendations. We appreciated the responsible approach and the time taken to test our application properly. Would definitely recommend working with Jalwan in the future.
Hristijan · Postiner Teampostiner.com
FAQ

Questions founders ask before booking

Straight answers on cost, process, and what you walk away with. Anything else, just ask.

Pricing depends on scope — the size of the application, number of user roles, and the depth of testing required. Most focused web app engagements land in a predictable range, and you always get a fixed quote before any work starts. No hourly surprises.

A clear report ranked by risk: a plain-language summary for you and your stakeholders, plus detailed findings for your engineers with steps to reproduce each issue, its business impact, and exactly how to fix it. Every finding is checked by hand.

Typically one to three weeks from kickoff to report, depending on scope. You get a defined timeline up front, and the average turnaround from testing to delivered report is around ten days.

Yes. Once your team ships fixes, I retest every finding to confirm the issue is genuinely closed and update the report. That verification is included in the engagement, not billed as an extra.

Yes. A formal penetration test with a professional report satisfies the pentest requirement for most compliance frameworks and customer security questionnaires, and gives you evidence you can share with auditors and prospects. I'm happy to sign an NDA and work under your security requirements first.

Ready to find your vulnerabilities before attackers do?

Book a security assessment and get a clear, prioritized picture of your application's real risk. No obligation, no automated-scan fluff.