Available for new engagements Remote · Worldwide
Services

Manual, impact-first security testing

Every engagement is a hands-on hunt — not a scanner report with a logo on it. I test the full OWASP surface, chase the highest-impact outcome the target allows, and hand you reproducible, prioritized findings you can actually act on.

Core

Web Application Penetration Test

A complete WSTG-driven assessment of your web app — authenticated and unauthenticated, across every role.

  • Authentication, session, MFA & password-reset flows
  • Access control — IDOR, privilege escalation, multi-tenant isolation
  • Injection — SQLi, SSTI, command, XXE
  • Business logic, race conditions & payment flows
  • Client-side — XSS, DOM, postMessage, prototype pollution
from $3,500
Core

API Security Testing

REST and GraphQL, mapped from your spec or reverse-engineered from a mobile/SPA backend.

  • OWASP API Top 10 — full coverage
  • BOLA / BFLA object & function-level authorization
  • Mass assignment & excessive data exposure
  • GraphQL introspection, batching & depth abuse
  • JWT flaws & rate-limit bypass
from $3,000

Source-Code Audit

Static review that reads the actual code and traces tainted input to real sinks — then validates each lead against a live target.

  • Dangerous sinks — deserialization, eval, template, raw SQL
  • Missing / broken authorization checks
  • Hardcoded secrets & crypto misuse
  • Language-specific footguns (JS, Python, PHP, Java, Go, Ruby)
from $5,000

Cloud & SaaS Configuration Review

The perimeter beyond the app — where a single misconfig becomes full compromise.

  • Subdomain / service takeover
  • Open & writable buckets, exposed management endpoints
  • SSRF-to-metadata & credential theft chains
  • IAM over-permissioning & assume-role abuse
from $3,000
Specialist

LLM / AI Feature Security

A high-value, low-competition surface most testers skip entirely.

  • Direct & indirect prompt injection
  • System-prompt extraction & jailbreak chains
  • Insecure tool / function-call abuse
  • RAG poisoning & excessive agency
from $4,000
Specialist

AI Agent Security

Harden the LLM agents you ship. I fuzz the agent's tool-use boundary to find where prompt-injection breaks it, then deploy corral — my fail-closed confinement kernel — so a compromised model can't reach your systems. Covers pydantic-ai, LangGraph, and custom loops.

  • Agent tool-use boundary fuzzing
  • Prompt-injection containment
  • corral fail-closed confinement-kernel deployment
  • pydantic-ai, LangGraph & custom agent loops
from $4,500
Ongoing

Continuous Attack-Surface Monitoring

Your surface changes weekly. This keeps watching after the test is over.

  • Recurring subdomain & asset discovery
  • Exposed-service & secret-leak alerting
  • Regression retesting of prior findings
  • Quarterly focused deep-dives
from $1,500 / mo
What you receive

Deliverables built to be acted on

A report is only useful if your engineers can fix from it. Every finding is self-contained, evidenced, and severity-honest.

  • Executive summary — risk posture in plain language for leadership.
  • Per-finding detail — description, CVSS, business impact, and step-by-step reproduction.
  • Real PoCs — captured live, with the exact request/response evidence.
  • Remediation guidance — specific, code-level fixes, not generic advice.
  • Coverage matrix — every test class marked tested / N-A, so you know what was actually looked at.
  • Free retest — I re-validate your fixes once, included.
Transparent pricing

Clear starting prices, scoped to your surface

Fixed-fee engagements — no hourly surprises. Starting prices below; your final quote is set by scope (endpoints, roles, tenants, environments) and confirmed in writing before any work begins.

Web Application Penetration Test
Full WSTG pass — authn/session, access control, injection, logic, client-side.
from $3,500
API Security Testing
REST & GraphQL — OWASP API Top 10, BOLA/BFLA, mass assignment, JWT.
from $3,000
External / Network VAPT
Internet-facing hosts & services — exposure, misconfig, known-CVE, weak creds.
from $2,500
Source-Code Audit
Taint-traced review to real, exploitable sinks — validated against a live target.
from $5,000
Cloud & SaaS Configuration Review
AWS/Azure/GCP — takeover, SSRF-to-metadata, IAM, tenant isolation.
from $3,000
LLM / AI Feature Security
Prompt injection, system-prompt extraction, insecure tool use, excessive agency.
from $4,000
AI Agent Security
Agent tool-loop fuzzing + corral confinement-kernel deployment. Prompt-injection containment for pydantic-ai / LangGraph / custom agents.
from $4,500

Or bundle it into a package

Focused Assessment
from $2,500

A single app, API, or specific concern — fast, deep, and tightly scoped.

  • One target / surface
  • Full WSTG or API Top 10 pass
  • Prioritized report + PoCs
  • One free retest
Request a quote
Full Pentest
from $12,000 · most popular

Your whole application estate — web, API, cloud, and auth — tested end to end.

  • Multi-surface: web + API + cloud
  • All roles & tenants
  • Executive + technical report
  • Remediation guidance + retest
  • Debrief call with your team
Book this
Continuous / Retainer
from $1,500 / mo

Ongoing testing and attack-surface monitoring as your product ships.

  • Recurring recon & monitoring
  • Quarterly deep-dives
  • Priority ad-hoc testing
  • hackz scanner deployment option
Let's talk

Prices in USD. Startups, non-profits & multi-service bundles — ask about tailored rates.

FAQ

Straight answers before we talk

The questions I get asked most. Anything else — just reach out.

How much does an engagement cost?

Every engagement is scoped to your actual attack surface, so pricing is a fixed custom quote — no open-ended hourly billing. Tell me the target and I'll return a firm price before any work begins.

How long does a test take?

A focused single-app or single-API assessment is typically one to two weeks end to end; a multi-surface estate takes longer. You get a firm timeline in the written scope before testing starts.

Do you work remotely?

Yes. All testing is performed remotely against your in-scope targets (staging or production by agreement), with a scoping call up front and a findings debrief over video at the end.

Are my data & findings confidential?

Always. I'm NDA-friendly, test only assets you explicitly authorize, and share reports solely with you. Nothing is disclosed publicly without your written consent.

Will testing disrupt production?

No. Testing is non-destructive and rate-limited by default. Anything higher-risk is agreed in the rules of engagement first, and destructive checks only run against non-production on request.

What do I receive at the end?

An executive summary, per-finding detail with CVSS and business impact, reproducible PoCs, code-level remediation guidance, a coverage matrix, and one free retest of your fixes.

Not sure which fits?

Send me a couple of lines about what you're building. I'll tell you honestly where I'd start and what a right-sized engagement looks like.

Start the conversation →