What the Audit Covers

Coverage follows OWASP ASVS Level 2

Authentication and Sessions

Signup, login, two-factor authentication, session lifecycle, and brute-force protection

Access Control and Business Logic

Authorization boundaries, access to other users' data, skipped exchange steps, and abuse of limits and rates

Input Validation and Injection

Handling of user-supplied data, injection, file uploads, XSS, and SSRF across exchange forms and orders

Cryptography and Data Protection

Storage and transport of personal and KYC data, secret handling, and TLS configuration

Configuration, Logging, and Errors

Server and framework settings, security headers, information leaks in responses, and logging of security-relevant events

APIs and Integrations

Public and internal APIs, webhooks, payment gateway integrations, and callback handling

How the Audit Works

Seven steps from agreeing the scope to verification by BestChange

  1. Together

    Scope and Access

    We agree on the boundaries, the environment, and the rules of engagement. For grey-box coverage you provide test accounts and a scope estimate: the number of REST API endpoints, the number of roles to test, and a general description of what the service does.

  2. On you

    Auditor Approval

    You tell BestChange that I will be your auditor and receive their confirmation.

  3. On me

    Testing

    I audit the security of the service using black-box and grey-box testing. I report critical findings as soon as I find them.

  4. On me

    Report

    You receive a report describing every finding with reproduction steps, a risk rating, and specific guidance on how to fix it.

  5. On you

    Remediation

    You fix the medium, high, and critical risk findings. Low-risk and informational items are left to your discretion.

  6. On me

    Retest

    I re-verify the affected areas and record the result in the final document, which confirms the issues are closed.

  7. On you

    BestChange Verification

    You submit the final report to BestChange for verification.

What You Get

Documents and an outcome

  • An audit report that meets BestChange requirements
  • Every finding described with reproduction steps and a risk rating
  • Specific remediation guidance — what to change and how
  • A retest of the fixes and a final document confirming that the issues are closed
  • Answers for your development team on the recommendations and how to implement them

Track Record

Every service I have audited passed the BestChange requirement with my report. Not one was rejected over the quality or completeness of the report.

Discuss Your Audit

Message me or book a short call — we will go over your service, the scope of the audit, and the timeline.