Ehtesham Ul Haq, founder of The Hidden Finds
Founder of The Hidden Finds

Ehtesham Ul Haq

Application Security Consultant
Founder, The Hidden Finds

About The Hidden Finds

Built To Find What Others Miss

The Hidden Finds was created after seeing a recurring problem across modern SaaS platforms and APIs:

Organizations often receive security reports filled with scanner output, while the vulnerabilities that actually matter remain undiscovered.

The focus became simple: identify real attack paths, validate exploitability, and provide findings that engineers can act on.

Founder-LedManual TestingSaaS & API FocusReal Exploitability
Why THF

Why Companies Work With The Hidden Finds

Direct senior involvement and practical product understanding without layers of generic delivery.

Founder Involvement

Scope, testing decisions, validation, and reporting remain connected to senior review.

Manual-First Investigation

Automation supports coverage, while important behavior and exploitability are validated manually.

Product-Risk Understanding

Findings are interpreted through roles, tenant models, sensitive data, and business workflows.

Practical Engineering Value

Reports prioritize reproduction, impact, remediation clarity, and efficient retesting.

Founder-Led ReviewsDirect involvement from scope through remediation.
SaaS & API SpecialistsFocused on modern product security.
Manual ValidationFindings verified beyond automated output.
Engineering-Ready ReportingReports built for remediation and retesting.
How We Think

Security Philosophy

Good security work should make product risk clearer, not bury teams beneath more output.

01

Real Exploitability

Findings should represent realistic attack paths rather than theoretical weaknesses.

02

Product Context

Security testing must understand how systems behave in practice.

03

Clear Communication

Reports should help engineering teams make decisions, not create confusion.

04

Practical Remediation

Every finding should include actionable guidance and retesting support.

Company Story

The Hidden Finds Journey

A steady focus on practical application security, direct delivery, and findings that improve real products.

2021

Established

Founded with a focus on practical application security testing.

2022

Broader Product Coverage

Expanded across SaaS applications, APIs, authentication, and access control reviews.

2023

Deeper Abuse-Case Work

Strengthened focus on IDOR, broken access control, business logic abuse, and API security.

2024

Founder-Led Workflows

Built deeper review workflows for SaaS and product teams.

2025

Clearer Consulting Delivery

Expanded structured services, positioning, and security consulting delivery.

Today

Practical Product Security

Founder-led reviews focused on exploitability, product risk, and engineering-ready remediation.

Specialization

What We Focus On

Focused expertise for security-sensitive product behavior across modern SaaS and API systems.

API

API Security Testing

REST and GraphQL authorization, object access, token scope, and data exposure.

Authorization

Access Control & IDOR

Role boundaries, ownership checks, tenant isolation, and privilege escalation.

Identity

Authentication Security

Login flows, sessions, recovery, token handling, and account takeover paths.

Workflows

Business Logic Testing

Valid product actions that can be chained or manipulated into unintended outcomes.

Applications

Application Security Testing

Manual testing across critical features, sensitive data paths, and user flows.

Exposure

Vulnerability Assessment

Validated weaknesses, exposed assets, prioritization, and remediation direction.

Founder-Led Review

Need Security Review From Someone Who Understands Product Risk?

Get practical security guidance grounded in real attack paths, business impact, engineering communication, and remediation support.

Direct Senior ReviewProduct-Risk ContextPractical RemediationRetesting Support