Security research
Testing a web application or API for authorization, authentication, OAuth, business-logic and injection issues, on your terms and in your scope.
Say what the system is, what you need, and what a good outcome looks like. I read everything the day it arrives and reply with a concrete next step.
Testing a web application or API for authorization, authentication, OAuth, business-logic and injection issues, on your terms and in your scope.
A pass over a product before launch, from someone who has shipped five and has spent months reading other people's for the same mistakes.
Found something in Clex, Clex AI, Driped, trgt, Modih Mail or this site? Tell me how to reproduce it. security.txt has the details.
Products, APIs, dashboards and Cloudflare-based systems that need to be built properly, with the security thinking in from the start.
For anything time-sensitive, email is fastest. For a vulnerability report, include steps to reproduce and I will acknowledge it within a few days.
Pick a topic, write a few plain sentences, and it lands in my inbox.