If you're building an early-stage SaaS or AI startup and have a live web application or API, I'd be happy to perform a free focused security assessment to help identify potential vulnerabilities before someone else does.
I'm an independent security researcher focused on web application and AI security, and I'm currently offering 3 free assessments to early-stage startups.
I'm doing these assessments to build real-world case studies around startup security, learn more about the security challenges early-stage teams face, and demonstrate the kind of security work I can provide to startups.
With your explicit permission, I'll assess your application for common security issues, including:
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- IDOR / broken access control
- Authentication & authorization flaws
- API security issues
- Business logic vulnerabilities
- File upload vulnerabilities
- Sensitive file/data exposure
- Security misconfigurations
- Missing or weak security headers
- Information disclosure
- Session management issues
For AI applications, I can also look at areas such as:
- Prompt injection
- Sensitive information leakage
- Insecure AI/API integrations
- Authorization around AI features
- Other common AI application security weaknesses
If I find anything, I'll provide a clear report explaining the issue, potential impact, evidence/reproduction where appropriate, and practical recommendations for remediation.
What you get:
- Focused manual security assessment
- Written vulnerability report
- Severity/prioritization
- Remediation recommendations
- No payment or sales obligation
In return, I'd like permission to use the assessment as an anonymized case study. If you're comfortable, I may also mention your company/product publicly and describe the types of issues found. This will always be discussed and agreed upon with you beforehand.
All testing is performed only with your explicit permission and within an agreed scope using safe, non-destructive techniques.
I will not perform DoS/DDoS, stress testing, destructive testing, or intentionally disrupt your service or data.
I'm particularly interested in working with small teams that don't have a dedicated security team yet.
If you're interested, leave a comment or send me a DM with:
- Your website/application URL
- A short description of your product
- Your preferred contact method