Available for engagements

I find the API and authorization flaws that automated scanners miss

Independent penetration tester and CVE author. Manual-first testing focused on access control, business logic, and the bugs that actually lead to breaches.

Request a Pentest contact@xitsec.in

Scoping reply within 24 hours. Testing can begin within days.

HackerOne
@alwayssmile
X / Twitter
@xitsec
0
Vulnerabilities Reported
0
Bug Bounty Programs
0
Manual Testing
0
Avg. Scoping Response
Trusted by security teams across industries

What I Test

Manual, expert-led penetration testing focused on the vulnerabilities that automated tools cannot find.

Web Application Pentest

End-to-end manual testing for logic flaws, injection, auth bypass, and business-logic vulnerabilities. You get a detailed report with reproduction steps and concrete fixes.

API & GraphQL Assessment Specialty

Deep-dive into REST, GraphQL, and gRPC APIs. Authentication, authorization on every resolver and endpoint, injection, rate-limiting, and schema-level exposure.

Authorization / IDOR / BOLA

Focused assessment of object-level and function-level access controls. The class of bug most scanners cannot find and most breaches exploit.

Continuous Retainer Testing

Ongoing security testing on a monthly retainer. New features, API changes, and deployments reviewed as they ship, not once a year.

Reports suitable for SOC 2, ISO 27001, and vendor security questionnaires.

How It Works

From scoping to remediation verification, here is what a typical engagement looks like.

Scoping

Submit your requirements. I reply within 24 hours with a clear scope, timeline, and fixed-price quote.

Testing

Manual-first methodology. Source review, data-flow tracing, every auth boundary tested by hand. Real bugs, not scanner noise.

Report

Each finding with severity, reproduction steps, root cause, and a concrete fix. Audit-ready format, no padded page counts.

Verify

After you remediate, I re-test to confirm each fix. Final clean report for your records or compliance audit.

Disclosed Vulnerabilities

Real bugs found, reported responsibly, and patched. Third-party verified.

Access Control

BetterDocs ≤ 4.1.1 — Missing Authorization to Private & Password-Protected Posts

Plugin: BetterDocs (WordPress) Patched: 4.1.2+
Missing authorization check allowed any authenticated user to read private and password-protected content. BetterDocs is active on 400,000+ WordPress installations.

Full researcher profile → wordfence.com/researchers/aaditya-banwari

How I Work

Authorized Testing Only

Every engagement starts with signed scope and rules of engagement. No testing outside agreed boundaries.

Confidentiality

Findings reported to you first. Nothing disclosed publicly without written consent. All test data deleted at engagement end.

Clear Deliverables

Written report: each finding with severity, reproduction steps, root cause, and a concrete fix. No scanner dumps.

Fast Turnaround

Solo operator, no scheduling queue. Scoping reply in 24 hours, testing can begin within days of agreement.

What Clients Say

Feedback from engineering and security leaders after completed engagements.

★★★★★
"Found three critical IDOR vulnerabilities in our payment API that two previous automated scans completely missed. The report was clear enough that our developers fixed everything in one sprint."
RM
Rahul M.
CTO, Fintech Startup (Series B)
★★★★★
"We needed a pentest report for SOC 2 compliance. Aaditya delivered in under a week — thorough, well-structured, and our auditor accepted it without questions. Already booked for our next cycle."
SP
Sarah P.
VP Engineering, SaaS Platform
★★★★★
"Most pentesters hand you a Burp Suite export. This was different — every finding had root cause analysis and a specific code-level fix. Our authorization model is fundamentally stronger now."
AK
Alex K.
Head of Security, Healthcare SaaS

Common Questions

How long does a typical pentest take?
Most web application tests take 5–10 business days depending on scope. API-only assessments are typically 3–7 days. You receive the full report within 2 business days of testing completion.
What do I get in the report?
Each finding includes severity rating, full reproduction steps (curl commands, screenshots), root cause analysis, and a concrete fix recommendation. The report is audit-ready for SOC 2, ISO 27001, and vendor security questionnaires.
Do you test on production or staging?
Both. I typically test on staging first for destructive tests, then verify findings on production. We agree on the approach during scoping — no surprises.
How much does a pentest cost?
Fixed-price quotes based on scope. A focused API assessment starts around $2,000. Full web application pentests typically range $3,000–$8,000. Monthly retainers are custom-priced. Submit a scoping request for an exact quote.
What happens if you find a critical vulnerability?
Critical findings are reported immediately via secure channel — not held until the final report. You get the details within hours of discovery so your team can start remediation right away.
Is re-testing included?
Yes. After you remediate, I re-test every finding at no additional cost and issue a clean verification report confirming the fixes.

Request a Pentest

Tell me what you need tested. I will reply with a scoping proposal and fixed-price quote within 24 hours.

Or email directly: contact@xitsec.in