The Hidden Finds

Built to uncover real security issues that most teams overlook.

The Hidden Finds is an application security-focused initiative providing SaaS security, API security testing, and vulnerability assessment for modern web platforms.

It was created with a clear focus: move beyond automated scans and generic reports, and instead uncover vulnerabilities that can be realistically exploited in production environments.

Founded by Ehtesham Ul Haq, an application security consultant, the work is centered around practical, hands-on testing — including penetration testing, API security analysis, and deep assessment of authentication and access control mechanisms.

The approach prioritizes identifying business logic flaws, broken access control, and real attack paths that impact how systems function and how users interact with them.

Rather than focusing on low-impact issues, The Hidden Finds emphasizes depth, clarity, and vulnerabilities that carry real security and business risk.

For a deeper look into the approach and background, see whoami.

Ehtesham Ul Haq
Application Security Consultant
Founder, The Hidden Finds

How The Hidden Finds Works

The Hidden Finds is an application security-focused initiative providing SaaS security, API security testing, penetration testing, and vulnerability assessment for modern web platforms.

Since 2021, the focus has been on helping SaaS companies, startups, and API-driven platforms identify real vulnerabilities that are often missed in routine security assessments.

Over time, The Hidden Finds has worked with a wide range of clients, delivering application security services and building strong relationships through practical, results-driven testing.

The approach goes beyond automated scans and generic reporting. Each assessment is centered around understanding how a system actually functions — how users interact with it, how APIs behave, and where real attack paths can exist.

This includes deep testing of authentication mechanisms, access control systems, and business logic — areas where critical vulnerabilities such as IDOR, broken access control, and workflow abuse commonly occur.

Rather than focusing on low-impact issues, the priority is identifying vulnerabilities that carry real security and business risk.

The Hidden Finds continues to evolve with modern technologies, cloud-based architectures, and emerging application patterns — ensuring that security testing remains relevant, practical, and aligned with how platforms are built today.

What We Focus On

The Hidden Finds focuses on identifying high-impact vulnerabilities in modern applications, APIs, and SaaS platforms — with an emphasis on real-world exploitability and business impact.

  • API Security Testing
    Identifying vulnerabilities in API endpoints, authentication, and data exposure.
  • Access Control & IDOR (BOLA)
    Detecting broken access control and unauthorized data access across user roles.
  • Authentication & Session Security
    Testing login flows, session handling, token management, and account takeover risks.
  • Business Logic Vulnerabilities
    Finding flaws in workflows, transactions, and system behavior that can be abused.
  • Application Penetration Testing
    Simulating real-world attacks to uncover exploitable weaknesses in web applications.
  • Vulnerability Assessment
    Systematic identification and prioritization of security risks across platforms.

Why Work With The Hidden Finds

Security is not just about finding vulnerabilities — it’s about understanding how they impact real systems and real users.

  • Focused on Real Vulnerabilities
    No noise, no low-impact findings — only issues that matter.
  • Manual Testing Approach
    No reliance on automated scans. Every assessment is hands-on and context-driven.
  • Deep Understanding of SaaS & APIs
    Built around modern architectures, user workflows, and integrations.
  • Clear, Actionable Findings
    Reports are practical, structured, and easy to understand.
  • Long-Term Security Mindset
    Not just finding issues — helping improve overall security posture.

Request a Security Review

Tell us what you’d like to assess — web application, API, authentication flow, or overall security posture. We’ll review your request and get back to you with the next steps.

Contact Us

The Hidden Finds helps businesses identify real security weaknesses across web applications, APIs, and digital assets — so you can operate with confidence and reduce risk.

Phone

+1(512) 518-0065

Email

info@thehiddenfinds.com

Address

30 N. Gould St., Ste. 7000
Sheridan, Wyoming 82801 United States