Application security review
Source review and hands-on testing of the code paths attackers try first.
- Sign-in, sessions, and account recovery
- Access control: IDOR, privilege escalation, tenant isolation
- Injection, SSRF, path traversal, and file uploads
- Payment flows and webhook signature checks
- API validation, rate limits, and error leakage