Independent penetration tester and CVE author. Manual-first testing focused on access control, business logic, and the bugs that actually lead to breaches.
Scoping reply within 24 hours. Testing can begin within days.
Manual, expert-led penetration testing focused on the vulnerabilities that automated tools cannot find.
End-to-end manual testing for logic flaws, injection, auth bypass, and business-logic vulnerabilities. You get a detailed report with reproduction steps and concrete fixes.
Deep-dive into REST, GraphQL, and gRPC APIs. Authentication, authorization on every resolver and endpoint, injection, rate-limiting, and schema-level exposure.
Focused assessment of object-level and function-level access controls. The class of bug most scanners cannot find and most breaches exploit.
Ongoing security testing on a monthly retainer. New features, API changes, and deployments reviewed as they ship, not once a year.
From scoping to remediation verification, here is what a typical engagement looks like.
Submit your requirements. I reply within 24 hours with a clear scope, timeline, and fixed-price quote.
Manual-first methodology. Source review, data-flow tracing, every auth boundary tested by hand. Real bugs, not scanner noise.
Each finding with severity, reproduction steps, root cause, and a concrete fix. Audit-ready format, no padded page counts.
After you remediate, I re-test to confirm each fix. Final clean report for your records or compliance audit.
Real bugs found, reported responsibly, and patched. Third-party verified.
Full researcher profile → wordfence.com/researchers/aaditya-banwari
Every engagement starts with signed scope and rules of engagement. No testing outside agreed boundaries.
Findings reported to you first. Nothing disclosed publicly without written consent. All test data deleted at engagement end.
Written report: each finding with severity, reproduction steps, root cause, and a concrete fix. No scanner dumps.
Solo operator, no scheduling queue. Scoping reply in 24 hours, testing can begin within days of agreement.
Feedback from engineering and security leaders after completed engagements.
Tell me what you need tested. I will reply with a scoping proposal and fixed-price quote within 24 hours.
Or email directly: contact@xitsec.in