Find the vulnerabilities before attackers do
I'm Jalwan — a freelance penetration tester who manually breaks web apps, APIs, and SaaS platforms so your team can fix what matters. Real exploits, clear reports, no automated-scan noise.
- Manual, human-led testing
- Developer-ready reports
- Free fix verification retest
- Security engagements delivered
- 30+Security engagements delivered
- Serious issues found & reported
- 100+Serious issues found & reported
- Years in application security
- 4Years in application security
- Average report turnaround
- 10 daysAverage report turnaround
Security testing built for modern applications
Focused, manual penetration testing for the products SaaS and startup teams actually ship — web apps, APIs, and multi-tenant platforms.
A transparent engagement, start to finish
- 01
Plan & agree scope
We agree exactly what gets tested, with a fixed price and timeline up front. I'll sign an NDA if you need one.
- 02
Explore your app
I go through your whole app the way an attacker would — every page, login, and user role.
- 03
Test by hand
I try to break in for real: stealing other users' data, bypassing logins, and abusing your app's logic. Every issue is proven, not guessed.
- 04
Report & walk you through it
You get a clear report ranked by risk, plus a call to explain what matters most and answer your team's questions.
- 05
Help you fix & re-check
I stay available while you fix things, then re-test every issue to confirm it's actually closed.
Reports your engineers will actually use
No 200-page tool printout — clear enough for you to understand, precise enough for your developers to fix.
Executive summary
A plain-language read on your risk posture that stakeholders and customers can follow.
Technical findings
Every issue with its severity, where it is, and clear steps to reproduce it — so your developers can act fast.
Remediation guidance
Prioritized fixes written for developers — not generic checklist advice.
Retest & attestation
Verification of every fix, plus an attestation letter for auditors and vendor reviews.
Broken Access Control — IDOR on /api/v1/invoices
200 OK — returns another tenant's invoice
Real results, real words
What teams say after an engagement — clear reports, honest severity, and fixes they could actually ship.
Jalwan conducted a detailed security assessment of our platform and identified several important issues we needed to address. The report was clear, well documented and included practical recommendations. We appreciated the responsible approach and the time taken to test our application properly. Would definitely recommend working with Jalwan in the future.
Questions founders ask before booking
Straight answers on cost, process, and what you walk away with. Anything else, just ask.
Pricing depends on scope — the size of the application, number of user roles, and the depth of testing required. Most focused web app engagements land in a predictable range, and you always get a fixed quote before any work starts. No hourly surprises.
A clear report ranked by risk: a plain-language summary for you and your stakeholders, plus detailed findings for your engineers with steps to reproduce each issue, its business impact, and exactly how to fix it. Every finding is checked by hand.
Typically one to three weeks from kickoff to report, depending on scope. You get a defined timeline up front, and the average turnaround from testing to delivered report is around ten days.
Yes. Once your team ships fixes, I retest every finding to confirm the issue is genuinely closed and update the report. That verification is included in the engagement, not billed as an extra.
Yes. A formal penetration test with a professional report satisfies the pentest requirement for most compliance frameworks and customer security questionnaires, and gives you evidence you can share with auditors and prospects. I'm happy to sign an NDA and work under your security requirements first.
Ready to find your vulnerabilities before attackers do?
Book a security assessment and get a clear, prioritized picture of your application's real risk. No obligation, no automated-scan fluff.