Jalaj Kumar Nimesh Application Security Discuss a VAPT ↗

Independent application security · CRTP · CWES

Web & API penetration testing.

I test authorization, authentication, tenant boundaries, APIs and business logic — then turn the findings into reproducible evidence your engineering team can act on.

Typical web + API VAPT ₹60,000–₹90,000 fixed quote after scope · one retest included

Selected work

Selected security findings.

Examples from authorized assessments and responsible disclosure. Sensitive implementation details are omitted where they are not public.

Passport Seva Portal Government of India

Authentication · responsible disclosure

Authentication bypass enabling unauthorized account access.

A weakness in the authentication flow made it possible to access another user account without possessing that user’s valid credentials.

Impact: account takeover · privately disclosed

Axis Bank Security research

Data exposure · responsible disclosure

Credit-card customer PII exposed beyond the intended access boundary.

A data-exposure issue allowed sensitive personally identifiable information associated with credit-card customers to be retrieved outside the intended access boundary.

Impact: customer PII exposure · privately disclosed

CVE-2026-72831 Public research

Incorrect authorization · public advisory

Low privilege → full administrative takeover.

A lower-privileged authenticated account could change a super administrator’s password or elevate privileges to administrative control.

CVSS 3.1: 8.8 High · NVD ↗ · Vendor advisory ↗

Confidential client B2B security platform

Authorized VAPT · access control

Cross-tenant authorization failure.

An authenticated user could perform user operations across customer tenants, breaking a core isolation boundary in a multi-tenant security product.

Impact: cross-tenant account operations · client identity confidential

Additional research acknowledged or rewarded by Red Hat, Blinkit, Utho, Survicate and MSG91.

Direct engagement

The person you speak with is the person who tests.

Security Engineer / Penetration Tester at BugBase, working across web and API assessments, exploitability analysis, vulnerability triage and remediation validation.

I scope the engagement, perform the testing, write the report and retest the fixes myself. There is no account-manager-to-tester handoff.

Direct access and lower overhead keep pricing lean without reducing testing depth.

CRTPCWES1.5+ years professional cybersecurity

VAPT pricing

Clear scope.
Fixed quote.

For a focused web + API product, most engagements fall in the range shown. Larger or multi-application scopes are quoted after review.

Typical web + API VAPT ₹60,000–₹90,000
one retest included
Coverage

Authentication, sessions, authorization, tenant isolation, APIs, business logic, high-risk workflows and relevant OWASP-class vulnerabilities.

Deliverables

Prioritized technical report, reproducible evidence, severity and business impact, remediation guidance, findings readout and one remediation retest.

Quote depends on

User roles, API surface, authentication model, workflow complexity and integrations. Targeted source-code review can be added when it materially improves coverage.

View representative finding format ↗ Synthetic example · no client data

Next step

Send the scope.
I’ll send a fixed quote.

Send the application type, user roles, API scope and preferred testing window. I’ll confirm the scope, timeline and price before testing begins.