Independent security researcher

I find the gaps between what an application allows and what it should.

I’m Arth Bajpai, founder of AB Labs. I perform evidence-led security testing across web applications, APIs, Android, iOS, desktop applications, and network environments.

Authorized testing only Available for select engagements
01AuthorizationIDOR · BOLA · BFLA
02Trust boundariesAuth · Session · Tenant
03Server-side pathsSSRF · Injection · Logic
01Impact firstPrioritize the paths that matter.
02Minimum harmProve safely, then stop.
03Reproducible evidenceMake every result defensible.

Track record

Proven at scale. Recognized by global security programs.

Hall of Fame recognition from Microsoft and Apple, alongside a public Bugcrowd record spanning 193 security programs.

1,420

Vulnerabilities

Reported on Arth’s public Bugcrowd researcher profile.

193

Security programs

Including 162 private Bugcrowd programs.

Public performanceBugcrowd · Aug 2026
#62Current rank
96.66%Accuracy
7,464All-time points

Selected Hall of Fame and program recognition.

Microsoft Apple Atlassian Pinterest Tripadvisor Upwork DocuSign Under Armour AMEX GBT Chipotle Vonage Seagate SimpliSafe Blackbaud AustralianSuper

Selected from Arth’s acknowledgements and the top engagements shown on his downloaded public Bugcrowd profile.

View public Bugcrowd profile
Achievement levels
P1 Warrior L4 Submission Shogun L9 Bounty Bee L7 Collaboration Crusader L1
Top target types
Web App 1,254 API Testing 102 Android 14 Network 4 iOS 3
Arth Bajpai, founder of AB Labs
Arth BajpaiFounder · AB Labs

About Arth

Independent researcher. Product-minded attacker.

I’m an India-based security researcher and the founder of AB Labs, focused on finding high-impact weaknesses across applications, APIs, mobile platforms, desktop software, and networks.

My work centers on authorization, authentication, business logic, and server-side trust boundaries—tested with minimum harm and documented with evidence engineering teams can reproduce.

India AB Labs Web · API · Mobile · Desktop · Network

Core expertise

Deep testing at the boundaries attackers actually target.

Focused reviews built around real product behavior—not scanner volume or generic checklists.

01

Authorization

Object, role, and tenant boundaries across APIs and complex workflows.

  • IDOR / BOLA
  • BFLA
  • Privilege escalation
02

Authentication

Account lifecycle testing from sign-in and recovery to session integrity.

  • Account takeover paths
  • OAuth / SSO
  • Session controls
03

Server-side trust

Input that crosses parsers, renderers, integrations, and internal fetch boundaries.

  • SSRF
  • Injection classes
  • Business logic
04
{ }

APIs & GraphQL

Function-first assessment of modern API contracts and resolver authorization.

  • REST APIs
  • GraphQL
  • Hidden functionality
05

Mobile, desktop & network

Security assessment across Android, iOS, desktop applications, network services, and the APIs and trust boundaries connecting them.

  • Android / iOS
  • Desktop applications
  • Network services

Engagements

Clear scopes. Decisive testing. Reports your team can use.

01

Web & API penetration testing

End-to-end review of application flows, REST and GraphQL APIs, roles, tenants, and high-impact server-side attack paths.

Full assessment
02

Android & iOS application testing

Assessment of mobile application behavior, local storage, transport, platform controls, and supporting backend APIs.

Mobile
03

Desktop & network security testing

Focused review of desktop applications, exposed services, network boundaries, configuration, and reachable attack paths.

Desktop & network
04

Targeted security review

A focused examination of authentication, authorization, GraphQL, integrations, or another critical boundary.

Focused depth
05

Remediation retesting

Independent confirmation that a fix closes the demonstrated path without leaving adjacent bypasses behind.

Verification

The AB Labs approach

Product understanding before payloads.

The strongest findings usually live inside the application’s intended behavior: who owns an object, which role may perform an action, where input crosses a trust boundary, and what happens next.

Every engagement is designed around safe validation, precise evidence, and a report that engineering teams can reproduce quickly.

  1. 01
    MapUnderstand functions, roles, objects, and trust boundaries.
  2. 02
    ChallengeTest the shortest plausible high-impact paths first.
  3. 03
    ProveCollect minimum safe, reproducible evidence.
  4. 04
    CommunicateDeliver clear impact, root cause, and remediation context.

Start a conversation

Have an application, API, or network that deserves a deeper look?

Available for authorized web, API, Android, iOS, desktop, and network security testing, focused reviews, and remediation verification.

Email me
cybersecurity@arthbajpai.com