Apply — security testing

The security bar is different.

You work inside a written scope, you stop where it stops, and a reviewer confirms each finding. Consent discipline comes first.

Written scopeWritten consentStop conditionsNDADisclosure history

The work

What the work is.

You test the agreed scope and write the finding in plain language, with the evidence attached. A senior reviewer confirms it.

The field map — six sub-categories

  • Web app pentestOWASP Top 10
  • API & auth abusesessions · tokens · IDOR
  • Cloud & infra configbuckets · headers · TLS · secrets
  • Data exposure & privacyPII · logs · backups
  • Supply chaindependencies · CI · third-party scripts
  • AI & LLM attack surfaceprompt injection · tool abuse

The bar

What we require.

Everything here is behaviour you can show us, not a claim you can make.

Disclosure history
A responsible disclosure or a write-up you can show us, with the timeline.
Methodology
You can explain how you work, step by step, without a tool doing the talking.
Scope discipline
You are comfortable with a written scope, and with the stop conditions inside it.
NDA
You sign an NDA before you see anything. We check references.

Non-negotiable

Rules of engagement.

  1. You test only what the written scope names.
  2. You stop the moment a stop condition triggers.
  3. Findings stay confidential, during the test and after.
  4. We check your references before your first scope.

Break one of these and the work ends. We say it now, not later.

Apply

Send your application.

Add one link we can read: a disclosure, a write-up, a report you wrote. Never a password.

Never put a password in this form.

The button opens a draft in your mail app. Nothing sends until you press send. If no draft opens, write to ubwebdevelopers@gmail.com.