Authorized security services

Test the attack paths that matter to your system.

Start with the system carrying the risk. I'll help shape a written scope across product security, infrastructure and cloud, or bounded Solidity/EVM readiness work.

Start an assessment enquiry

Choose a starting point

Choose the assessment that fits your system.

Scope, duration, and price are set per engagement, after a short scoping call once the inputs below are known.

01

Product security

Assess the application, the identities using it, and the APIs or engineering decisions behind it as one product boundary.

  • Web & APIs
  • Mobile
  • Architecture & code
  • Business logic
  • Web Application & API Assessment
  • Mobile Application Security Assessment
  • Application Security Review & Advisory
See assessment details

Applications

Web Application & API Assessment

Test authentication, authorization, business logic, sensitive-data handling, and server-side attack paths across an agreed application scope.

  • Web applications
  • REST and GraphQL APIs
  • Identity and access control
  • Business-logic abuse
Who it is for
Product and engineering teams preparing a release, validating a high-risk change, or investigating recurring authorization and business-logic concerns.
What you receive
A coverage record, observations, and any validated findings with reproducible evidence, severity rationale, and remediation guidance.
What I need to start
A staging environment where possible, API documentation, architecture context, representative test roles, and a named authorization owner.
Evidence behind it
OSWE credential record, public web and API vulnerability research, and Finder-credited advisories linked in the Research Ledger.

Mobile

Mobile Application Security Assessment

Review an Android application, its local data and trust boundaries, and its supporting APIs. iOS work is offered only after a scope-fit review.

  • Android; iOS after scope-fit review
  • Local storage and transport
  • Authentication flows
  • Backend API behavior
Who it is for
Teams that need the installed application, local trust boundaries, authentication flow, and supporting APIs assessed as one system.
What you receive
Coverage, observations, and any validated mobile or backend findings with a remediation-focused technical readout.
What I need to start
Installable builds, supported test devices or platform details, test accounts, backend/API context, and a safe test environment.
Evidence behind it
eMAPT credential record, Android and Flutter application review, and application and API testing experience. iOS depth is confirmed during fit review.

Engineering enablement

Application Security Review & Advisory

Turn security questions into repeatable engineering decisions through threat modeling, architecture review, focused source-to-sink code review, remediation planning, and security consulting.

  • Threat modeling
  • Architecture and design review
  • Secure development practices
  • Remediation workshops
Who it is for
Engineering and leadership teams that need a threat model, design decision, focused code review, remediation plan, or security-practice workshop.
What you receive
A decision-ready risk map and prioritized actions that engineering, product, and leadership can use.
What I need to start
Architecture context, decision goals, relevant diagrams or code, known threats, delivery constraints, and the people who own remediation.
Evidence behind it
OSWE credential record and public source-to-sink vulnerability case studies, with Finder credit linked to primary advisories.
02

Infrastructure & cloud

Trace reachable services, identity and privilege paths, segmentation, wireless exposure, and selected cloud controls.

  • Network & identity
  • Wireless
  • AWS · Azure · GCP
  • IAM & segmentation
  • Network, Identity & Wireless Assessment
  • Cloud Security Review & Scoped Assessment
See assessment details

Infrastructure

Network, Identity & Wireless Assessment

Evaluate reachable services, identity and trust paths, segmentation, and wireless exposure within documented technical and physical boundaries.

  • External and internal networks
  • Active Directory
  • Segmentation and trust paths
  • Wireless by location and fit
Who it is for
Organizations validating an external perimeter, internal attack paths, identity controls, PCI segmentation, or a defined wireless location.
What you receive
An attack-path view of tested routes, observations, and any validated weaknesses, plus a practical hardening sequence.
What I need to start
Approved ranges and locations, network or identity diagrams where available, test accounts, exclusions, and operational stop conditions.
Evidence behind it
OSEP, OSCP/OSCP+, CPTS, and OSWP credential records, enterprise infrastructure experience, and the public seg-test workflow.

Cloud review

Cloud Security Review & Scoped Assessment

Review named AWS, Azure, or Google Cloud accounts and services for identity paths, public exposure, storage, network boundaries, logging, and selected configurations. This is a bounded review, not blanket cloud assurance.

  • Named AWS, Azure, or Google Cloud accounts and services
  • IAM identities, roles, and privilege paths
  • Network and public-service exposure
  • Storage, logging, and selected controls
Who it is for
Teams with a specific security question about a landing zone, internet-facing workload, identity model, migration, or remediation cycle within identified accounts, subscriptions, or projects.
What you receive
A scoped record of the identities, services, trust boundaries, and configurations reviewed, plus validated findings, prioritized remediation, coverage limits, and agreed retest guidance.
What I need to start
A named authorization owner, agreed accounts, subscriptions, or projects, architecture context, service inventory, exclusions, and preferably time-bound test identities, read-only roles, or customer-exported configuration evidence.
Evidence behind it
The review applies infrastructure, identity, segmentation, web, API, and application-security methods where they fit. Provider, service, and review depth must match the available capability and evidence access.
03

Smart-contract readiness

Review a bounded Solidity/EVM snapshot before deployment or alongside a mature specialist audit program.

  • Solidity & EVM
  • Roles & invariants
  • DeFi attack paths
  • Foundry or Hardhat PoCs
  • Solidity/EVM Smart Contract Security Readiness Review
See assessment details

Smart contracts

Solidity/EVM Smart Contract Security Readiness Review

Review an agreed Solidity/EVM code snapshot for implementation and business-logic weaknesses, then reproduce validated issues in an isolated environment. This readiness review does not replace formal verification or a mature protocol-audit program.

  • Solidity/EVM contracts, roles, trust boundaries, and invariants
  • Reentrancy, access control, and external call or delegatecall paths
  • Oracle, flash-loan, frontrunning, and governance attack paths
  • Foundry or Hardhat test-based PoCs where appropriate
Who it is for
Teams preparing a bounded Solidity/EVM release, reviewing defined modules, or seeking a focused second review alongside a mature audit program.
What you receive
A scope and coverage matrix, trust-boundary and invariant notes, validated findings with isolated test-based PoCs where appropriate, remediation guidance, a technical readout, one agreed retest, and explicit coverage limits.
What I need to start
An exact repository commit or archive, compiler and toolchain details, architecture and invariant notes, role definitions, external dependencies, intended chain and deployment state, and a safe local fork or testnet where needed.
Evidence behind it
Provider-verifiable Smart Contract Hacking training covering both parts of the curriculum: 33 hours, 50 hands-on exercises, and an 87/100 final assessment. No public production protocol-audit record is claimed.

Report and evidence

Review the deliverable before you enquire.

The sample is fictional. Public research, tools, and credentials provide separate evidence of the work behind it.

How an engagement works

Four steps from scope to verification.

  1. 01

    Agree the scope

    Confirm ownership, objectives, targets, exclusions, access, communication, stop conditions, and permitted techniques in writing.

  2. 02

    Assess

    Combine manual testing with targeted tooling while minimizing service and data impact.

  3. 03

    Report

    Deliver validated findings, reproducible evidence, severity reasoning, and prioritized remediation guidance.

  4. 04

    Review and verify

    Walk through the results and record the status of agreed fixes selected for retesting.

Defined scope · clear evidence

Bring the system and the question you need answered.

Share the system type, desired outcome, timing, and authorization owner. I can confirm fit before exchanging sensitive details.

Start an assessment enquiry