Every engagement is a hands-on hunt — not a scanner report with a logo on it. I test the full OWASP surface, chase the highest-impact outcome the target allows, and hand you reproducible, prioritized findings you can actually act on.
A complete WSTG-driven assessment of your web app — authenticated and unauthenticated, across every role.
REST and GraphQL, mapped from your spec or reverse-engineered from a mobile/SPA backend.
Static review that reads the actual code and traces tainted input to real sinks — then validates each lead against a live target.
The perimeter beyond the app — where a single misconfig becomes full compromise.
A high-value, low-competition surface most testers skip entirely.
Harden the LLM agents you ship. I fuzz the agent's tool-use boundary to find where prompt-injection breaks it, then deploy corral — my fail-closed confinement kernel — so a compromised model can't reach your systems. Covers pydantic-ai, LangGraph, and custom loops.
Your surface changes weekly. This keeps watching after the test is over.
A report is only useful if your engineers can fix from it. Every finding is self-contained, evidenced, and severity-honest.
Fixed-fee engagements — no hourly surprises. Starting prices below; your final quote is set by scope (endpoints, roles, tenants, environments) and confirmed in writing before any work begins.
A single app, API, or specific concern — fast, deep, and tightly scoped.
Your whole application estate — web, API, cloud, and auth — tested end to end.
Ongoing testing and attack-surface monitoring as your product ships.
Prices in USD. Startups, non-profits & multi-service bundles — ask about tailored rates.
The questions I get asked most. Anything else — just reach out.
Every engagement is scoped to your actual attack surface, so pricing is a fixed custom quote — no open-ended hourly billing. Tell me the target and I'll return a firm price before any work begins.
A focused single-app or single-API assessment is typically one to two weeks end to end; a multi-surface estate takes longer. You get a firm timeline in the written scope before testing starts.
Yes. All testing is performed remotely against your in-scope targets (staging or production by agreement), with a scoping call up front and a findings debrief over video at the end.
Always. I'm NDA-friendly, test only assets you explicitly authorize, and share reports solely with you. Nothing is disclosed publicly without your written consent.
No. Testing is non-destructive and rate-limited by default. Anything higher-risk is agreed in the rules of engagement first, and destructive checks only run against non-production on request.
An executive summary, per-finding detail with CVSS and business impact, reproducible PoCs, code-level remediation guidance, a coverage matrix, and one free retest of your fixes.
Send me a couple of lines about what you're building. I'll tell you honestly where I'd start and what a right-sized engagement looks like.
Start the conversation →