For business · B2B

REST API security audit and team training
in security and automation

I find real vulnerabilities in your APIs — BOLA, IDOR, authorization flaws — and teach your team to close them before release. Plus corporate training in test automation with Playwright, JavaScript and Jenkins. Everything is hands-on, built around real-world cases and common vulnerabilities — not dry theory.

Typical program budget: €3,000 — €15,000 depending on scope and timeline.

Three ways to work together

Pick one format or combine them into a program for your team.

01 · Audit

REST API security audit

I test your API the way an attacker would.

  • Authentication, authorization and ownership logic
  • BOLA / IDOR, mass assignment, access to other users’ data
  • Dangerous bulk operations and excessive data exposure
  • Business logic flaws and vulnerable fields
What you get A report with reproduction steps for every finding, priorities and a fix plan.
02 · Training

Team training: BOLA and XSS

I teach developers and QA to catch vulnerabilities before release — using real-world API and web form examples.

  • How to find BOLA / IDOR and role-based access flaws
  • Where XSS hides: forms, rich text, search, admin UI
  • Negative API checks, not just the happy path
  • A minimal pre-release security pass
What you get Checklists, test examples and a basic security regression the team keeps.
03 · Training

API / UI test automation

Corporate training in test automation with Playwright, JavaScript and Jenkins.

  • API checks, UI E2E, negative scenarios
  • Test architecture, stable assertions, helpers
  • Jenkins / CI: runs on PR, reports, artifacts
  • Hands-on practice with real automation tasks
What you get A working pipeline and a team that knows how to maintain and grow it.

When you need this

The most common situations companies come with.

Your API is public and untested

The product is growing, the API is open to clients and partners, but there has been no systematic security testing — or the last audit is badly outdated.

Bugs and incidents in production

Regression does not cover critical flows, incidents hurt reputation and revenue, and the same root causes repeat release after release.

The team lacks security testing skills

QA checks the happy path, developers do not know what BOLA or XSS looks like in their own code, and no one owns the process.

Automation is stuck

Tests are flaky, the pipeline is unstable, coverage is not growing — and releases keep falling back on manual work.

How we work

A transparent process without unnecessary bureaucracy. NDA — no problem.

1

Intro call

Goals, team setup, tech stack, NDA and timeline constraints.

2

Assessment and plan

What you already have, where the bottlenecks are, which format gives the most value. We agree on scope and budget.

3

Audit / training

I run the audit or training in the agreed format: reports, checklists and materials stay with your team.

4

Results

Report, fix plan, metrics. Follow-up support and next steps if needed.

Free consultation

A short call: we go through your context, pick the right format — audit, training or a mix — and agree on a budget range. If I’m not the right fit for your task, I’ll say so directly.

✉ vitali@brunovski.com

Request form

Prefer email? Fill in the form below. I reply by email or messenger within one business day.

By clicking the button you agree to data processing needed to answer your request. See Privacy for details.