Security Web App Evaluation (Read description)

via Freelancer ·

Budget / Salary£20–250
TypeFreelance project
LocationRemote
Posted1 hour ago
I have a demo SAST web application that needs a third-party review of its security posture. The goal is to measure how well the platform detects real issues, how often it raises false positives, and how effective the built-in AI-assisted remediation suggestions are. I also want an expert perspective on the soundness of the underlying technical architecture.

During the assessment, please:
• Probe detection quality with well-crafted test cases and known vulnerable samples.
• Document every false positive you encounter, explaining why it is incorrect and how it could be avoided.
• Stress-test the AI remediation flow, noting accuracy, clarity, and any missing defensive guidance.
• Comment on scalability, data flow, and overall architecture from an AppSec best-practice standpoint (e.g., OWASP SAMM, NIST 800-53 where relevant).

Deliverables
1. A detailed technical report (PDF) that covers methodology, findings, evidence, and prioritised recommendations.
2. A one-page executive summary of key risks.
3. A signed statement of findings on your company letterhead (scanned copy acceptable).

Acceptance criteria
• Report must map each finding to a CVSS or equivalent severity rating.
• All screenshots, logs, or PoC snippets must be time-stamped.
• Letterhead document must include your full name, title, company address, and signature.

Kindly indicate the primary tools you plan to use (Burp Suite, OWASP ZAP, custom scripts, etc.) and an estimated timeline. I’m ready to start as soon as you confirm availability.
web security computer security technical writing internet security penetration testing documentation technical documentation risk assessment ai auditing security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.