Web application testing
Manual assessment of authentication, authorization, sessions, input handling and business logic, focused on the paths with the greatest impact.
Available for selected engagements
INDEPENDENT SECURITY TESTING · BUG BOUNTY
I help product teams uncover meaningful weaknesses in web applications and APIs — with reproducible evidence, clear risk context and an actionable path to remediation.
Authorized testing only · NDA available · English
Clear scope and authorization
Responsible disclosure
Developer-ready reporting
ENGAGEMENTS
The scope follows your product stage, critical user journeys and actual threat model.
Manual assessment of authentication, authorization, sessions, input handling and business logic, focused on the paths with the greatest impact.
REST and GraphQL review for BOLA/IDOR, excessive data exposure, access control, rate limits and process abuse.
Vulnerability validation, false-positive reduction, impact reproduction and support with a safe, accurate response.
THE PROCESS
We agree on goals, critical flows, environments, test accounts, constraints and a secure communication channel.
I map the attack surface and manually validate scenarios, documenting only reproducible results.
You receive a clear description, reproduction steps, impact, evidence and practical remediation guidance.
After remediation, I verify closure and regression risk, with a clear outcome for business and engineering.
ANATOMY OF A STRONG REPORT
Each card is the anatomy of a finding — issue, impact, evidence, fix. Representative of the work I do, not a specific client engagement.

ABOUT
I focus on testing web applications and APIs, with particular attention to access control, authentication and business logic — with ongoing authorization research across WordPress, Elastic, GitLab and Matomo.
By day I work as a SOC L2 analyst at Jagiellonian University — a blue-team background that shapes how I test: I read source code, run every proof of concept in a local lab before filing, and report only what I actually measured.
Every engagement is grounded in explicit authorization, minimal operational impact and responsible disclosure. A good report should help fix the problem — not merely prove it exists.
FOCUS AREAS
VERIFIABLE PROOF
FAQ
No. Every commercial engagement requires an agreed scope and explicit authorization. In bug bounty programs, I stay strictly within the published policy.
When the scope requires it, production testing is performed carefully under agreed rules of engagement. I prefer test accounts, agreed windows and low-impact techniques.
A report with an executive summary and technical detail: reproduction steps, evidence, impact, priority and remediation recommendations.
After a short conversation about scope, architecture, user roles and timing. A fixed price works for a well-defined scope; phased pricing is also possible.
HAVE A PRODUCT TO TEST?
Tell me what the product is, what should be in scope and the timing you have in mind. I will reply with the questions needed for a reliable estimate.
contact@jakubkozub.comI usually reply within 1–2 business days.