Have you built a web application using AI toolsThe ability of an AI system to use external tools, services or functions. More, no-code/low-code platforms or rapid development, and want to know whether it contains serious security issues?
I offer a basic security review of a smaller web application focused on common OWASP Top 10A list of common and important web application risks, used as a map for security reviews. More risks, authenticationIdentity verification. A service checks whether you really are who you claim to be. More and authorizationThe decision about what a logged-in user may see or do. More issues, sessionThe period after login when a service remembers you as a logged-in user. More handling, inputs, API endpoints and typical problems in applications built or heavily accelerated with AI.
The goal is to quickly and practically identify issues that could lead to data leaks, access control bypasses, API abuse, account takeover or accidental exposure of sensitive information.
Who this service is for
- a startup or small team before launching a new web application
- an AI/vibe-coded MVP that works, but security was not the main priority
- a smaller SaaS, internal tool, client portal or admin interface
- a project assembled by multiple people or AI toolsThe ability of an AI system to use external tools, services or functions. More without a clear security design
- an application that handles user accounts, personal data, payments, orders or non-public content
What I review
- loginThe information used to log in to a service, usually username, email, password, code, or security ke... More, registration, passwordIn general, a password is an arbitrary string of characters including letters, digits, or other symb... More reset and sessionThe period after login when a service remembers you as a logged-in user. More handling
- authorizationThe decision about what a logged-in user may see or do. More, roles, permissions and separation of user data
- common OWASP Top 10A list of common and important web application risks, used as a map for security reviews. More risks
- inputs, forms, uploads, parameters and API endpoints
- basic configuration of security headers, cookiesA small piece of data stored in the browser. A site can use it to remember login, settings, or a tra... More, CORS and TLS
- publicly accessible parts of the application and accidentally exposed information
- typical issues in AI-generated or rapidly assembled code
Scope
- one smaller web application
- one domainA human-readable name for an internet service, such as a website address. More or one testing/production environment
- up to 3 user roles
- up to 5 main application flows
- basic review of the API used by the application
What you receive
- a prioritized findings report
- a clear summary of the main risks
- specific remediation recommendations
- a distinction between critical issues and less important improvements
- a final consultation to discuss the review results
Delivery
Typical delivery is within 7 business days after the scope is confirmed and the required access is provided.
For larger or more complex applications, we can agree on an extended security test individually.
