Web Security · 2024
Web Application Vulnerability Assessment
XSS · IDOR · Access Control
Open to work — security assessments & collaboration
bhautikpatel1201@gmail.comRecognized by NASA & Huawei for responsible disclosure
I'm Bhautik Patel — a Security Analyst who performs manual web, API and mobile penetration testing. My research has been acknowledged by NASA, Huawei, Sony, Honda, Daimler Truck, Mistral AI, Supabase, the State of California and more. You get the vulnerabilities automated scanners miss, in a report your developers can act on the same day.
Security Analyst & Bug Bounty Hunter
Open to work
Letters of Appreciation — NASA
For responsibly disclosed security vulnerabilities.
Security research recognized by
Services
Specialized security services focused on identifying, validating, and responsibly disclosing real-world vulnerabilities.
Manual security testing of web applications to identify XSS, IDOR, authentication, and business logic flaws.
Explore FeaturedTesting REST and GraphQL APIs for authorization issues, broken authentication, and data exposure vulnerabilities.
ExploreAndroid & iOS testing for insecure data storage, certificate validation issues, hardcoded secrets, and insecure API communication.
ExploreIn-depth manual testing focused on logic flaws that automated scanners often miss.
ExploreActive vulnerability research across public bug bounty programs with responsible disclosure practices.
ExploreSecurity testing, scripting, and automation using Linux and Bash for efficient vulnerability discovery.
ExploreHelping teams understand security risks and apply effective remediation strategies.
ExploreClear and professional reporting of vulnerabilities, including reproduction steps and remediation guidance.
ExploreEngagement options
Every engagement is scoped individually — transparent coverage, clear deliverables, no surprises.
| Engagement | Web Application Pentest | API Security Assessment | Mobile App Pentest |
|---|---|---|---|
| Coverage | XSS, IDOR, authentication & access control, business logic flaws | REST & GraphQL — BOLA/IDOR, broken auth, mass assignment, data exposure | Android & iOS — insecure storage, certificate validation, hardcoded secrets, insecure API traffic |
| Methodology | Manual testing aligned to OWASP Top 10 + DOM analysis | Manual testing aligned to OWASP API Top 10, JWT analysis, rate limiting | Static + runtime analysis with Frida and Objection |
| Primary tools | Burp Suite, manual testing | Burp Suite, Postman | Frida, Objection, MobSF |
| Report with PoCs | ✓ Included | ✓ Included | ✓ Included |
| Remediation guidance | ✓ Included | ✓ Included | ✓ Included |
| Retest of fixes | ✓ Included | ✓ Included | ✓ Included |
| Engagement type | Per scope — request a quote | Per scope — request a quote | Per scope — request a quote |
Not sure which fits? Send me your stack — I'll tell you honestly what you need.
How it works
Understanding application scope, attack surface mapping, asset discovery, and identifying technologies, endpoints, and entry points.
Initial phase
Mapping potential threat vectors based on application logic, authentication flows, authorization controls, APIs, and mobile components.
Short planning cycle
Deep manual testing for XSS, IDOR, access control flaws, business logic issues, API weaknesses, and mobile-specific security risks.
Core testing phase
Validating findings, assessing impact, preparing clear proof-of-concepts, and responsibly reporting vulnerabilities to stakeholders.
Final phase
Hall of Fame
Each recognition below represents a real vulnerability — found, responsibly disclosed, and formally acknowledged.
Critical vulnerability, responsibly disclosed · 2025
Security vulnerability disclosure
State of California
Hall of Fame
Mistral AI
Hall of Fame
About me
I am a cybersecurity professional focused on real-world attack scenarios, manual penetration testing, and responsible disclosure.
My expertise includes Web Application Security, API Security Testing, JavaScript security issues, and bug bounty hunting — actively hunting on HackerOne and Bugcrowd.
Bulwarkers Web Security Private Ltd · 2023 — Present
Conduct manual web and API penetration testing, identify security vulnerabilities, and submit responsible disclosure reports.
HackerOne / Bugcrowd · 2023 — Present
Actively hunting and responsibly disclosing vulnerabilities across multiple platforms.
Bulwarkers Web Security Private Ltd · Aug 2023 — Jan 2024
Assisted in vulnerability assessments and security testing under senior analysts.
Selected work
Selected security research, vulnerability assessments, and responsible disclosure work across web, API, and mobile applications.
Web Security · 2024
XSS · IDOR · Access Control
API Security · 2024
BOLA · Auth Bypass
Mobile Security · 2023
Android · iOS
Research · 2024
Bug Bounty · Responsible Disclosure
Write-ups & research
How I discovered an unauthorized file-access vulnerability in a NASA system and received an official Letter of Appreciation for the responsible disclosure.
Read on MediumA full walkthrough of discovering and exploiting a misconfigured Amazon S3 bucket leading to takeover — including the recon and methodology behind the find.
Read on MediumFAQ
Scanners find known patterns. I find what they can't: business-logic abuse, chained low-severity issues that become account takeovers, and authorization flaws that need a human to understand your application's intent. Every finding is manually validated — no false-positive noise.
A clear, professional report with each vulnerability's impact, reproduction steps, and remediation guidance — the same reporting standard recognized by the security teams at NASA and Huawei. After your team fixes the issues, I retest and confirm the fixes hold.
Per scope. Tell me your application type, size, and timeline — I'll respond with a clear scope and quote. If your application doesn't need a full assessment yet, I'll tell you that honestly.
Yes — I'm based in India and work fully remote with clients worldwide. All testing is performed under written authorization, within agreed scope, and findings are reported privately to you only.
It depends on scope and complexity. A focused API or web assessment typically takes 3–7 days of active testing, with the report delivered within 2 business days after testing concludes. Larger or more complex applications take longer — I'll give you a realistic timeline upfront.
Absolutely. All engagements are conducted under a written agreement with strict confidentiality. Findings are reported only to you, and I do not disclose or discuss your application's vulnerabilities with any third party without your explicit written consent.
Need help identifying or fixing security issues? Let's work together to improve your security posture.
Contact
Get in touch for security assessments, vulnerability research, or professional collaboration opportunities. I reply within 24 hours.
India (Remote — worldwide)
Available on request