Manual penetration test: multi-tenant authorization and access control (Laravel healthcare SaaS)
Worldwide
I need a focused manual penetration test of a multi-tenant healthcare web application before a September launch. This is a targeted authorization-focused engagement, not a full-scope test. I am not looking for automated scanner output. About the application Server-rendered Laravel (PHP-FPM) on AWS: CloudFront and WAF, Application Load Balancer, ECS Fargate, RDS MariaDB, S3. No separate REST API. Roughly [X] web routes. It is a B2B SaaS platform for medical practices. Each practice is a tenant. Every patient record, note, appointment, and invoice belongs to exactly one practice, and no practice should ever see another practice's data. There are seven user roles: patient, provider, medical assistant, practice manager, billing, marketing, and admin. What I need tested, in priority order Tenant isolation. Can a user authenticated at Practice A reach any data belonging to Practice B by manipulating IDs in URLs, form parameters, or requests? Broken object level authorization within a tenant. Can a patient reach another patient's records? Can a lower-privileged role reach records they should not? Role boundary enforcement across all seven roles, including whether restrictions are enforced server-side or only hidden in the UI. Authentication and session management: login, MFA, session handling, password reset, account enumeration. File upload handling. The app accepts CSV and XLSX imports. Please test for formula injection, path traversal, malicious file content, and parser abuse. Webhook endpoints. Signature verification on inbound webhooks from payment and third-party services. Environment and access Grey box, fully authenticated. I will provide credentials for two separate test practices and for every role, against a staging environment configured like production. Staging contains synthetic test data only. No real patient data will be present at any point. Deliverables required Findings report with severity ratings (CVSS), reproduction steps, and request and response evidence for each finding Remediation guidance my developer can act on One round of retesting after fixes, included A short call or written summary walking me through the findings Timeline Code freeze is August 25. Testing can begin August 26. I need findings by roughly September 1 so there is time to remediate and retest before launch. Requirements OSCP, OSWE, or equivalent hands-on certification Demonstrated manual testing of multi-tenant SaaS authorization, not scanner-based assessments Willing to sign an NDA Please include a sanitized sample report or a description of what your report contains In your proposal, please answer: how do you test tenant isolation specifically, and what do you need from me to do it well?
- Less than 30 hrs/weekHourly
- 1-3 monthsDuration
- ExpertExperience Level
$60.00
-
$110.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:15 to 20
- Last viewed by client:1 hour ago
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- United StatesNew York6:16 PM
- $2K total spent11 hires, 3 active
- 42 hours
- Mid-sized company (10-99 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by