Authorized, fixed-scope review of a small web application and its APIs. I test authentication, authorization, IDOR/BOLA, session handling, input validation, business logic, REST, GraphQL and WebSocket endpoints, and exposed configurations. You receive manually verified findings, reproducible evidence, severity and business impact, remediation guidance, and one focused retest. Testing begins only after written authorization and agreed rules of engagement.