Open to work — security assessments & collaboration

Recognized by NASA & Huawei for responsible disclosure

Find your security flaws
before attackers do.

I'm Bhautik Patel — a Security Analyst who performs manual web, API and mobile penetration testing. My research has been acknowledged by NASA, Huawei, Sony, Honda, Daimler Truck, Mistral AI, Supabase, the State of California and more. You get the vulnerabilities automated scanners miss, in a report your developers can act on the same day.

  • 100% manual testing
  • Clear, reproducible reports
  • Responsible disclosure
Bhautik Patel — Security Analyst

Bhautik Patel

Security Analyst & Bug Bounty Hunter

Open to work

Vulnerability reports
0+
Reports
Years of experience
0+
Years
Recognitions
0+
Recognitions
NASA

Letters of Appreciation — NASA
For responsibly disclosed security vulnerabilities.

Security research recognized by

NASA Huawei Sony Red Bull Starbucks Booking.com Intercom Braze Linktree

Engagement options

Choose the right assessment

Every engagement is scoped individually — transparent coverage, clear deliverables, no surprises.

Comparison of web, API, and mobile security assessment engagements
Engagement Web Application Pentest API Security Assessment Mobile App Pentest
Coverage XSS, IDOR, authentication & access control, business logic flaws REST & GraphQL — BOLA/IDOR, broken auth, mass assignment, data exposure Android & iOS — insecure storage, certificate validation, hardcoded secrets, insecure API traffic
Methodology Manual testing aligned to OWASP Top 10 + DOM analysis Manual testing aligned to OWASP API Top 10, JWT analysis, rate limiting Static + runtime analysis with Frida and Objection
Primary tools Burp Suite, manual testing Burp Suite, Postman Frida, Objection, MobSF
Report with PoCs ✓ Included ✓ Included ✓ Included
Remediation guidance ✓ Included ✓ Included ✓ Included
Retest of fixes ✓ Included ✓ Included ✓ Included
Engagement type Per scope — request a quote Per scope — request a quote Per scope — request a quote
Get a scoped quote

Not sure which fits? Send me your stack — I'll tell you honestly what you need.

How it works

A proven 4-step testing workflow

  1. Reconnaissance & Scope Analysis

    Understanding application scope, attack surface mapping, asset discovery, and identifying technologies, endpoints, and entry points.

    Initial phase

  2. Threat Modeling & Test Planning

    Mapping potential threat vectors based on application logic, authentication flows, authorization controls, APIs, and mobile components.

    Short planning cycle

  3. Manual Security Testing

    Deep manual testing for XSS, IDOR, access control flaws, business logic issues, API weaknesses, and mobile-specific security risks.

    Core testing phase

  4. Validation & Responsible Disclosure

    Validating findings, assessing impact, preparing clear proof-of-concepts, and responsibly reporting vulnerabilities to stakeholders.

    Final phase

Hall of Fame

Trusted by the security teams of global organizations

Each recognition below represents a real vulnerability — found, responsibly disclosed, and formally acknowledged.

NASA
★ Letter of Appreciation

NASA

Critical vulnerability, responsibly disclosed · 2025

Huawei
★ Letter of Appreciation

Huawei

Security vulnerability disclosure

  • Sony Hall of Fame
  • Red Bull Hall of Fame
  • State of California Hall of Fame
  • Mistral AI Hall of Fame
  • Supabase Hall of Fame
  • Honda Hall of Fame
  • Daimler Truck Hall of Fame
  • Starbucks Bug Bounty
  • Booking.com Bug Bounty
  • Intercom Bug Bounty
  • Braze Bug Bounty
  • Linktree Bug Bounty
  • Razorpay Bug Bounty
  • + more Additional private programs
    (under NDA)
0+
Vulnerability reports
0+
Recognitions
0
Letters of Appreciation
0+
Organizations secured

About me

Securing applications & real-world systems

I am a cybersecurity professional focused on real-world attack scenarios, manual penetration testing, and responsible disclosure.

My expertise includes Web Application Security, API Security Testing, JavaScript security issues, and bug bounty hunting — actively hunting on HackerOne and Bugcrowd.

Experience
2+ Years
Degree
MCA — Cybersecurity, Parul University
Education
BCA, VNSGU (2019–2022)
Based in
India (Remote)
Availability
Open to Work

Professional journey

Sr. Security Analyst

Current

Bulwarkers Web Security Private Ltd · 2023 — Present

Conduct manual web and API penetration testing, identify security vulnerabilities, and submit responsible disclosure reports.

Bug Bounty Hunter

HackerOne / Bugcrowd · 2023 — Present

Actively hunting and responsibly disclosing vulnerabilities across multiple platforms.

Security Intern

Bulwarkers Web Security Private Ltd · Aug 2023 — Jan 2024

Assisted in vulnerability assessments and security testing under senior analysts.

Core skills

Web Application Security95%
API Security Testing90%
Manual Penetration Testing88%
Android / iOS Penetration Testing85%
Linux & Bash80%

Selected work

Security research & assessments

Selected security research, vulnerability assessments, and responsible disclosure work across web, API, and mobile applications.

Web application vulnerability assessment

Web Security · 2024

Web Application Vulnerability Assessment

XSS · IDOR · Access Control

REST API security testing

API Security · 2024

REST API Security Testing

BOLA · Auth Bypass

Android and iOS application testing

Mobile Security · 2023

Android & iOS Application Testing

Android · iOS

Bug bounty vulnerability research

Research · 2024

Bug Bounty Vulnerability Research

Bug Bounty · Responsible Disclosure

FAQ

Common questions

How is manual testing different from an automated scan?

Scanners find known patterns. I find what they can't: business-logic abuse, chained low-severity issues that become account takeovers, and authorization flaws that need a human to understand your application's intent. Every finding is manually validated — no false-positive noise.

What do I receive at the end of an engagement?

A clear, professional report with each vulnerability's impact, reproduction steps, and remediation guidance — the same reporting standard recognized by the security teams at NASA and Huawei. After your team fixes the issues, I retest and confirm the fixes hold.

How are engagements priced?

Per scope. Tell me your application type, size, and timeline — I'll respond with a clear scope and quote. If your application doesn't need a full assessment yet, I'll tell you that honestly.

Do you work with remote / international clients?

Yes — I'm based in India and work fully remote with clients worldwide. All testing is performed under written authorization, within agreed scope, and findings are reported privately to you only.

How long does a typical engagement take?

It depends on scope and complexity. A focused API or web assessment typically takes 3–7 days of active testing, with the report delivered within 2 business days after testing concludes. Larger or more complex applications take longer — I'll give you a realistic timeline upfront.

Is my application data kept confidential?

Absolutely. All engagements are conducted under a written agreement with strict confidentiality. Findings are reported only to you, and I do not disclose or discuss your application's vulnerabilities with any third party without your explicit written consent.

Secure your application

Need help identifying or fixing security issues? Let's work together to improve your security posture.

Start your project

Contact

Let's talk about your security

Get in touch for security assessments, vulnerability research, or professional collaboration opportunities. I reply within 24 hours.

Location

India (Remote — worldwide)

Call me

Available on request

Please enter your name.
Please enter a valid email address.
Please enter a subject.
Please enter your message.