One-Time Lending Portal Security Audit
Budget / Salary$1,500–3,000
TypeFreelance project
LocationRemote
Posted1 hour ago
Our in-house team is wrapping up a custom lending portal that consolidates every stage of the loan lifecycle and provides separate dashboards for investors, borrowers, and brokers. Because the platform stores and exchanges highly-sensitive documents—personal IDs, financial records, and legal agreements—I need an independent specialist to run a single, thorough security review right before we move to production.
My top priority is verifying that data encryption is rock-solid at rest and in transit. In addition, each role (investor, borrower, broker) has its own workflow, so you’ll need to confirm that our access-control logic keeps information strictly segregated.
What I expect from you
• Pen-test and code-level review focused on encryption implementation (TLS, key management, database-level encryption, file-storage encryption)
• Validation that role-based permissions cannot be escalated or bypassed
• Vulnerability report with severity ranking, reproduction steps, and practical remediation guidance
• A follow-up call to walk me through findings and recommended fixes
Acceptance criteria
1. All critical and high-severity issues clearly documented with actionable remediation steps.
2. Encryption routines confirmed to meet current NIST or industry-equivalent standards.
3. Verification that investor, borrower, and broker users cannot retrieve or modify data outside their scope.
Tech stack details, staging credentials, and architecture diagrams will be provided once we sign an NDA. Looking forward to your expertise in locking this platform down before launch.
We are looking to hire someone by late November or early December.
My top priority is verifying that data encryption is rock-solid at rest and in transit. In addition, each role (investor, borrower, broker) has its own workflow, so you’ll need to confirm that our access-control logic keeps information strictly segregated.
What I expect from you
• Pen-test and code-level review focused on encryption implementation (TLS, key management, database-level encryption, file-storage encryption)
• Validation that role-based permissions cannot be escalated or bypassed
• Vulnerability report with severity ranking, reproduction steps, and practical remediation guidance
• A follow-up call to walk me through findings and recommended fixes
Acceptance criteria
1. All critical and high-severity issues clearly documented with actionable remediation steps.
2. Encryption routines confirmed to meet current NIST or industry-equivalent standards.
3. Verification that investor, borrower, and broker users cannot retrieve or modify data outside their scope.
Tech stack details, staging credentials, and architecture diagrams will be provided once we sign an NDA. Looking forward to your expertise in locking this platform down before launch.
We are looking to hire someone by late November or early December.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.