
Independent Web Application Security Verification — Fixed Scope
- or -
Post a project like this23
£88(approx. $118)
- Posted:
- Proposals: 10
- Remote
- #4518060
- Awarded
Full-Stack AI Developer | Web Apps & Mobile Apps, MVPs, AI Agents & Automations
AI Engineer | Data Science & Machine Learning Expert | AI Solutions & Predictive Analytics
1109516813053733119433661367494411973068133108819062789128449071251934111729491
Description
Experience Level: Expert
Hi,
I have a stable pre-production privacy-sensitive SaaS application called BenariWell, built with React/TypeScript and Supabase (authentication, PostgreSQL/RLS, private storage and signed URLs).
The application has already undergone extensive internal automated, adversarial and authenticated browser testing. I have a prepared external-reviewer evidence pack, so I am not looking for development work or a general open-ended security audit.
I need an independent security tester to verify a defined scope using synthetic test data only.
Required scope:
• Manually execute a predefined temporary-file deletion test covering 4 pathways (A–D) and 5 negative controls (NC1–NC5).
• Authentication and session handling.
• Sign-out/session invalidation.
• Cross-account and cross-case BOLA/IDOR testing.
• Supabase Row Level Security (RLS) and access-control testing.
• Private storage permissions.
• Signed URL access/security.
• CSP and security-header review.
• Confirm that Account B cannot access Account A’s cases, results, evidence or stored files.
• Review the deletion audit trail and confirm deletion is only recorded as successful after the required post-deletion verification.
I require a written evidence-based result showing PASS / FAIL / BLOCKED for the defined controls, with evidence/references for the tests performed.
I will provide:
• stable candidate build;
• synthetic test accounts;
• detailed execution instructions;
• deletion verification pack;
• internal evidence index.
No real patient data will be provided or used.
This is verification/testing only — not development work.
Before I purchase/accept an offer, please confirm:
1. Can you perform the manual tests above rather than only running an automated vulnerability scanner?
2. Are you comfortable testing Supabase RLS, authentication and BOLA/IDOR?
3. Can you execute the supplied A–D / NC1–NC5 deletion controls?
4. Will you provide evidence for each control and a final PASS/FAIL/BLOCKED report?
5. What is your lowest fixed price for this defined scope?
6. How long would you need?
Thank you.
I have a stable pre-production privacy-sensitive SaaS application called BenariWell, built with React/TypeScript and Supabase (authentication, PostgreSQL/RLS, private storage and signed URLs).
The application has already undergone extensive internal automated, adversarial and authenticated browser testing. I have a prepared external-reviewer evidence pack, so I am not looking for development work or a general open-ended security audit.
I need an independent security tester to verify a defined scope using synthetic test data only.
Required scope:
• Manually execute a predefined temporary-file deletion test covering 4 pathways (A–D) and 5 negative controls (NC1–NC5).
• Authentication and session handling.
• Sign-out/session invalidation.
• Cross-account and cross-case BOLA/IDOR testing.
• Supabase Row Level Security (RLS) and access-control testing.
• Private storage permissions.
• Signed URL access/security.
• CSP and security-header review.
• Confirm that Account B cannot access Account A’s cases, results, evidence or stored files.
• Review the deletion audit trail and confirm deletion is only recorded as successful after the required post-deletion verification.
I require a written evidence-based result showing PASS / FAIL / BLOCKED for the defined controls, with evidence/references for the tests performed.
I will provide:
• stable candidate build;
• synthetic test accounts;
• detailed execution instructions;
• deletion verification pack;
• internal evidence index.
No real patient data will be provided or used.
This is verification/testing only — not development work.
Before I purchase/accept an offer, please confirm:
1. Can you perform the manual tests above rather than only running an automated vulnerability scanner?
2. Are you comfortable testing Supabase RLS, authentication and BOLA/IDOR?
3. Can you execute the supplied A–D / NC1–NC5 deletion controls?
4. Will you provide evidence for each control and a final PASS/FAIL/BLOCKED report?
5. What is your lowest fixed price for this defined scope?
6. How long would you need?
Thank you.
Mary D.
0% (0)Projects Completed
-
Freelancers worked with
-
Projects awarded
100%
Last project
2 Sep 2026
United Kingdom
New Proposal
Login to your account and send a proposal now to get this project.
Log inClarification Board Ask a Question
-
There are no clarification messages.
We collect cookies to enable the proper functioning and security of our website, and to enhance your experience. By clicking on 'Accept All Cookies', you consent to the use of these cookies. You can change your 'Cookies Settings' at any time. For more information, please read ourCookie Policy
Cookie Settings
Accept All Cookies


