Break it on purpose.
Ship it with proof.
ExploitQA is an independent security assurance practice. I hunt the flaws an attacker would actually use: broken access control, authorization gaps, injection, auth and business-logic bugs. I prove each one by hand, and retest until it's closed.
Findings summary
scope: app.acme.exampleSecurity measured like quality, not guessed at.
QA teams don't ship a feature because it compiles. They prove it works. Security deserves the same bar: find the real defect, demonstrate the impact, and confirm the fix holds. That's the whole method.
Finding-led, by hand
Scanners catch the obvious and miss the interesting. I test the logic a tool can't reason about: access control, multi-step flows and trust boundaries, and chain small weaknesses into real impact.
Proven, not theoretical
No speculative "mediums." Every reported issue comes with a working proof-of-concept and the exact request that triggers it, so your team can reproduce it in minutes.
Tracked to closed
Findings move Open → Verified → Fixed on a board you can see. When you've patched, I retest (no extra charge) and sign off only when it's genuinely resolved.
The bug classes that actually breach software.
Most real incidents don't come from exotic zero-days. They come from access control and authorization done wrong. That's where I spend the most time, backed by full OWASP coverage.
Broken access control
IDOR and object-level authorization across tenants and users.
Improper authorization
Missing function-level checks, privilege escalation, hidden admin APIs.
Authentication & sessions
Token forgery, weak secrets, session fixation, reset abuse.
Injection
SQL, command, SSTI and server-side template and header injection.
Business & payment logic
Price tampering, race conditions, workflow and ledger abuse.
API security
BOLA, BFLA, mass assignment, excessive data exposure.
Server-side request forgery
Internal pivots, metadata theft, cloud credential exposure.
Secrets & misconfiguration
Leaked keys, permissive CORS, exposed admin and debug surfaces.
Pick the depth your release needs.
Scoped to your stack and timeline, from a focused pre-launch check to a full black-and-grey-box assessment of a production system.
Application & API penetration test
A full manual assessment of your web app and its APIs, authenticated and unauthenticated, across every role, mapped to OWASP and reported with reproducible PoCs.
- Access control & authorization tested per role, per object
- Auth, session, injection and business-logic coverage
- Executive summary plus engineer-ready technical detail
- Free retest and written sign-off once fixed
API & auth review focused
Deep dive on tokens, sessions and object/function-level authorization across your API surface.
Fintech & payments assurance regulated
Money-movement logic, ledger integrity, KYC and tenant isolation, tested the way an attacker chasing funds would.
Pre-launch security QA pre-ship
A fast, targeted check before a release, with a clear go / no-go on the risks that matter.
A clear path from scope to sign-off.
Scope
Targets, roles, rules of engagement and a safe test window, agreed in writing.
Map
Recon the attack surface: endpoints, roles, trust boundaries and data flows.
Exploit
Manual testing and real exploitation, chaining weaknesses into business impact.
Report
Ranked findings, each with a reproducible PoC and concrete remediation.
Retest
Confirm every fix, close the board, and sign off on what's resolved.
A report your team can act on the same day.
- Risk-ranked findingsSorted by real exploitability and business impact, not raw CVSS alone.
- Reproducible PoCsThe exact requests, steps and payloads to reproduce each issue.
- Remediation guidanceSpecific, framework-aware fixes your engineers can apply directly.
- Retest & attestationA short letter confirming resolved issues, useful for customers and auditors.
Rahul Joshua
I'm a security engineer who treats offensive testing as a quality discipline. I've run hands-on assessments across fintech platforms and SaaS products, the places where a single broken authorization check moves money or leaks a whole customer base. I work directly with your engineers, keep findings practical, and don't hand over a report I wouldn't want to receive myself.
Know your software holds before someone tests it for you.
Tell me what you're shipping and where you're worried. I'll come back with a scope, a timeline and a fixed price.
rahuljoshua77@gmail.com