For business · B2B
REST API security audit and team training
in security and automation
I find real vulnerabilities in your APIs — BOLA, IDOR, authorization flaws — and teach your team to close them before release. Plus corporate training in test automation with Playwright, JavaScript and Jenkins. Everything is hands-on, built around real-world cases and common vulnerabilities — not dry theory.
Typical program budget: €3,000 — €15,000 depending on scope and timeline.
Three ways to work together
Pick one format or combine them into a program for your team.
01 · Audit
REST API security audit
I test your API the way an attacker would.
- Authentication, authorization and ownership logic
- BOLA / IDOR, mass assignment, access to other users’ data
- Dangerous bulk operations and excessive data exposure
- Business logic flaws and vulnerable fields
What you get
A report with reproduction steps for every finding, priorities and a fix plan.
02 · Training
Team training: BOLA and XSS
I teach developers and QA to catch vulnerabilities before release — using real-world API and web form examples.
- How to find BOLA / IDOR and role-based access flaws
- Where XSS hides: forms, rich text, search, admin UI
- Negative API checks, not just the happy path
- A minimal pre-release security pass
What you get
Checklists, test examples and a basic security regression the team keeps.
03 · Training
API / UI test automation
Corporate training in test automation with Playwright, JavaScript and Jenkins.
- API checks, UI E2E, negative scenarios
- Test architecture, stable assertions, helpers
- Jenkins / CI: runs on PR, reports, artifacts
- Hands-on practice with real automation tasks
What you get
A working pipeline and a team that knows how to maintain and grow it.
When you need this
The most common situations companies come with.
Your API is public and untested
The product is growing, the API is open to clients and partners, but there has been no systematic security testing — or the last audit is badly outdated.
Bugs and incidents in production
Regression does not cover critical flows, incidents hurt reputation and revenue, and the same root causes repeat release after release.
The team lacks security testing skills
QA checks the happy path, developers do not know what BOLA or XSS looks like in their own code, and no one owns the process.
Automation is stuck
Tests are flaky, the pipeline is unstable, coverage is not growing — and releases keep falling back on manual work.
How we work
A transparent process without unnecessary bureaucracy. NDA — no problem.
1
Intro call
Goals, team setup, tech stack, NDA and timeline constraints.
2
Assessment and plan
What you already have, where the bottlenecks are, which format gives the most value. We agree on scope and budget.
3
Audit / training
I run the audit or training in the agreed format: reports, checklists and materials stay with your team.
4
Results
Report, fix plan, metrics. Follow-up support and next steps if needed.