
Open
Posted
•
Ends in 6 days
Paid on delivery
I need a comprehensive vulnerability assessment and penetration test performed on my production web application. Because I can grant limited internal knowledge—such as architecture diagrams, sample credentials, and API documentation—I would like the engagement run as a grey box exercise rather than pure black-box reconnaissance. 1 External VA/PT - 4 public IPv4/region - Full manual validation through WAF/security stack 2 Internal VA/PT - 10 segments / 250 live IPs - Credentialed + non-credentialed testing 3 Web Application — Virtual Trust - 1 app / 20 modules / 10 roles - Grey/white box + targeted production validation 4 Web Application — CrimsonLogic - 1 app / 20 modules / 10 roles 5 API Security 50 endpoints base - Full OWASP API Top 10 + business logic 7 Configuration Review Agreed security components - Firewall/WAF/API/cloud/security configurations 8 AI/LLM - 1 app / 1 model / 5 interfaces / 1 RAG / 5 tools - Comprehensive OWASP-aligned LLM security 9 Agentic AI - 1 Excessive agency/tool/function security 10 Production - 1 controlled validation pass - Non-destructive 11 DR - 1 targeted validation During DR exercise 12 Remediation - 1 cycle / ≤10 C&H findings - Evidence-based retest 13 Reporting - 1 final report + executive report - Technical evidence + remediation
Project ID: 40685648
8 proposals
Open for bidding
Remote project
Active 4 mins ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
8 freelancers are bidding on average ₹55,156 INR for this job

Hello, I can conduct a comprehensive grey-box Vulnerability Assessment & Penetration Testing (VAPT) engagement covering your infrastructure, web applications, APIs, configurations, and AI/LLM environment, with production testing carefully controlled and non-destructive. Scope & Approach • External VAPT: 4 public IPv4s with manual validation through WAF/security controls. • Internal VAPT: 10 segments / 250 live IPs with credentialed & non-credentialed testing. • Web Apps: Virtual Trust & CrimsonLogic 20 modules/10 roles each; authenticated testing, access control, session security, business logic & production validation. • API Security: 50 endpoints; OWASP API Top 10, authentication, authorization & business logic. • Configuration Review: Firewall, WAF, API, cloud & agreed security components. • AI/LLM: 1 model, 5 interfaces, RAG & 5 tools; OWASP-aligned security assessment. • Agentic AI: Excessive agency, tool/function permissions & authorization boundaries. • Production/DR: Controlled non-destructive validation and targeted DR exercise testing. • Remediation: One retest cycle for up to 10 Critical/High findings. • Reporting: Technical + executive reports with evidence, severity, impact, attack paths and remediation. Deliverables Evidence-based findings covering affected assets, validation/reproduction details, business impact, risk ratings and actionable remediation guidance. Regards, Kajal Majhi
₹225,000 INR in 7 days
5.6
5.6

We provide detailed vulnerability assessment and technical review of existing security controls for all targeted systems and assets are provided with this service. in the assessment, our team will present a comprehensive vulnerability report, a logical network connection drawing, a complete cyber asset inventory and recommended mitigation actions. What you will get with this project? - Full assessment report with all vulnerability, recommendation, test cases and Observations in detail. - Kindly contact me to get sample report. Waiting for your reply for further discussion. Thanks & Regards, Keyur
₹33,750 INR in 7 days
0.6
0.6

Hi, New on Freelancer — 20 years of development experience behind us. We're taking our first few projects here at a fraction of our normal rate purely to build our review history. You get senior agency work at junior pricing; we get a review. Straight trade. Given the complexity of web application environments, potential API vulnerabilities are often overlooked but can be critical entry points. I'd start with a thorough examination of your API endpoints for any misconfigurations or outdated security protocols. Can you provide access details or any specific areas of concern?
₹25,000 INR in 7 days
0.0
0.0

Hi, I’m new to the Freelancer platform, but I have 2+ years of hands-on experience in cybersecurity and VAPT. I have worked on Web, API, Android and infrastructure security assessments, including manual testing, vulnerability validation, PoC development, risk assessment, and professional security reporting. I can handle the assessment end-to-end, from understanding the scope and attack surface to identifying and validating vulnerabilities, preparing detailed findings, remediation recommendations, and supporting revalidation. Although I’m new to Freelancer, I’m not new to this field. I would really appreciate the opportunity to work on this project and demonstrate the quality of my work. Looking forward to working with you.
₹25,000 INR in 10 days
0.0
0.0

India, India
Payment method verified
Member since Nov 24, 2025
₹12500-37500 INR
₹12500-37500 INR
₹150000-250000 INR
₹75000-150000 INR
₹75000-150000 INR
₹750-1250 INR / hour
$250-750 USD
₹1500-12500 INR
₹1500-12500 INR
£250-750 GBP
$15-25 USD / hour
£18-36 GBP / hour
₹1500-12500 INR
$30-250 USD
$10-15 CAD
£20-250 GBP
₹750-1250 INR / hour
$30-250 AUD
£20-250 GBP
$30-250 USD
₹37500-75000 INR
$250-750 USD
₹600-1500 INR
£250-750 GBP
€250-750 EUR