Services
I provide independent security consulting for businesses. All work is performed under written contract and explicit authorization from the system owner.
Penetration Testing
Authorized assessments of web applications, APIs, and network infrastructure. Scope is agreed in writing before any testing begins.
Application Vulnerability Research
In-depth analysis of client-owned applications to identify security weaknesses, with severity ratings mapped to CVSS and concrete remediation steps.
Security Code Review
Manual review of source code and architecture for security defects, plus advisory on secure design and threat modeling.
How Engagements Work
- Scoping call — we define exactly which systems are in scope.
- Written contract and authorization-to-test, signed by both parties.
- Testing window, with regular status updates and immediate disclosure of critical findings.
- Written technical report delivered electronically.
- Remediation support and optional retest.
Pricing is per engagement (fixed fee, based on scope) or hourly for smaller scopes of work. Invoices are issued on completion or at agreed milestones.
No testing is ever performed without written permission from the owner of the target systems. I do not sell offensive tooling or exploit code.
Contact
See the Contact page to start a conversation about an engagement.