Work with me
Security engagements
Authorized, ethical security testing for teams with Rust or web codebases. Fixed scope, real reports, responsible disclosure. The same eye I bring to finding CVEs, pointed at your stack.
Rust / web security audit
A fixed, one-week deep review of a Rust service or web app.
- Threat model and prioritized findings report
- Reproductions and concrete remediation guidance
- A live readout call with your engineers
- timeline
- 1 week, fixed scope
- price
- Request a quote
Web-app penetration test
Authorized, scoped testing of a web application end to end.
- Authenticated and unauthenticated testing within agreed scope
- Severity-rated findings with proof-of-concept
- Retest of fixes after remediation
- timeline
- 1–2 weeks, scoped
- price
- Request a quote
Bug-bounty triage / AppSec retainer
Ongoing triage and security partnership for product teams.
- Monthly triage of incoming reports
- Vulnerability validation and fix guidance
- Quarterly review of your security posture
- timeline
- Monthly retainer
- price
- Request a quote
How an engagement works
Every engagement is authorized and scoped in writing. No surprises, no grey areas.
- 01
Scope & authorization
We agree the targets, rules of engagement, and written authorization before anything is tested.
- 02
Testing
Hands-on, methodical testing within scope — the same depth I bring to bug-bounty work.
- 03
Reporting
A clear report: severity-rated findings, reproductions, and concrete remediation guidance.
- 04
Responsible disclosure
Findings stay between us. Nothing is published without your sign-off.
Have something that needs testing?
Book a 30-minute call and we'll scope it together.