[{"data":1,"prerenderedAt":635},["ShallowReactive",2],{"site-content:en":3},{"nav":4,"hero":18,"headings":35,"intro":42,"blog":43,"reasonsToHire":63,"coverage":81,"services":96,"engagementFaq":449,"process":469,"about":484,"contact":494,"privacy":539,"cta":632},{"services":5,"research":6,"blog":7,"about":8,"contact":9,"menu":10,"close":11,"skip":12,"language":13,"home":14,"privacy":15,"roles":16,"serviceDetails":17},"Services","Track record","Blog","About","Contact","Menu","Close","Skip to content","Choose language","Home","Privacy","Roles & research collaboration","View service",{"eyebrow":19,"lines":20,"lead":24,"primary":25,"secondary":26,"readout":27},"Penetration testing for SaaS and product teams",[21,22,23],"Find out what an attacker","can reach in your app","\u003Cem>before you ship it.\u003C\u002Fem>","I test web apps and APIs for the flaws scanners miss: broken access control, tenant isolation and business logic. You work directly with me, from scoping to the final walkthrough.","Request a proposal","See my track record",{"title":28,"items":29,"note":34},"Public record you can check",[30,31,32,33],"150+ security vulnerabilities reported","7 Facebook & Instagram vulnerabilities acknowledged by Meta","9 Linux kernel patches in mainline, including fixes for 2 CVEs","Built Hendra, a context-aware DAST scanner","You deal with me from the first call to the final report. Scope, price and dates are agreed in writing before I start.",{"evidence":36,"expertise":37,"work":38,"research":39,"experience":40,"contact":9,"process":41},"Expertise you can verify","Choose the work your product needs","Vulnerabilities I reported, and fixes I wrote","The scanner I built and the research behind it","Engineering & security experience","From your first question to a useful result","Penetration tests and security code review for web, mobile and desktop software, plus fuzzing, fix verification and custom security tooling. I have reported 150+ security vulnerabilities, and I run every engagement myself. Scope, price and dates are agreed in writing before I start.",{"title":44,"lead":45,"latest":46,"readArticle":47,"allArticles":48,"all":49,"categories":50,"published":54,"updated":55,"author":56,"sources":57,"contents":58,"relatedService":59,"empty":60,"titleLatest":61,"related":62},"Application security blog","CVE explainers, code review patterns and practical guidance for people who build and own software.","Latest articles","Read article","All articles","All",{"cve":51,"guides":52,"news":53},"CVE explainers","Practical guides","Security news","Published","Updated","Author","Sources","In this article","Need this checked in your own product?","No articles in this category yet.","How I review real vulnerabilities","Related reading",{"title":64,"lead":65,"items":66},"Why a researcher who also builds software","Scanners report symptoms. I trace each finding to the code that causes it and to a fix your developers can ship.",[67,72,77],{"title":68,"body":69,"evidence":70,"href":71},"I find the cause, then write the fix.","I wrote the patches behind two Linux kernel CVEs and seven more fixes now in mainline. On your product, each finding comes with the code path, the conditions that trigger it and a fix your team can review.","See the 9 merged kernel patches","\u002Fresearch#kernel-patches",{"title":73,"body":74,"evidence":75,"href":76},"I build software, so my fixes fit your codebase.","I have led web development and designed a DAST scanner from its architecture up. When I recommend a fix, I have already considered how your team will implement and test it.","See how I built Hendra","\u002Fresearch\u002Fhendra",{"title":78,"body":79,"evidence":25,"href":80},"The person who scopes your test runs it.","I agree the scope with you, run every test myself and walk your developers through each finding.","\u002Fcontact",{"title":82,"items":83},"Web and API first. Mobile and native when your product needs it.",[84,88,92],{"title":85,"body":86,"href":87},"Web & APIs","Authentication, permissions, sensitive workflows and the application behind your API. My strongest and preferred area of practice.","\u002Fservices\u002Fweb-application-security-assessment",{"title":89,"body":90,"href":91},"Mobile applications","The application, its local data and its connection to backend services, with the platform and API boundaries agreed explicitly.","\u002Fservices\u002Fmobile-application-security-assessment",{"title":93,"body":94,"href":95},"Desktop & native software","Application code, libraries and components handling untrusted input. C, C++ and Java projects scoped around the risks that matter.","\u002Fservices\u002Fdesktop-application-security-assessment",[97,128,165,201,235,268,301,332,366,407],{"slug":98,"keywords":99,"type":103,"featured":104,"title":105,"summary":106,"audience":107,"fit":108,"tags":109,"scope":112,"deliverables":116,"faq":121},"application-penetration-testing",[100,101,102],"application penetration testing","freelance pentester","web mobile desktop pentest","application-pentest",true,"Application penetration testing","Find out how weaknesses in your web, mobile or desktop application could affect your users, data and business. Receive confirmed findings and clear priorities for fixing them.","For product owners, CTOs and development teams preparing a release, responding to a customer assessment request or checking an existing product.","Before a release, customer review or important product change.",[85,110,111],"Mobile","Desktop",[113,114,115],"Define the product, versions, environments, access and permitted testing.","Investigate relevant attack paths, trust boundaries and security-sensitive functionality.","Validate findings and explain their impact within the agreed scope.",[117,118,119,120],"An assessment report with confirmed findings, evidence and reproduction steps.","Priorities grounded in the affected product and the impact of each finding.","Practical fix guidance and a walkthrough with your technical team.","A record of tested areas, scope limitations and agreed next steps.",[122,125],{"question":123,"answer":124},"Can you test web, mobile and desktop applications?","Yes. Share the product, platform and goal. We will define the targets, methods and access appropriate to your application. Web and API security are my strongest and preferred area of practice.",{"question":126,"answer":127},"What if we only need one feature checked?","We can scope a focused review of a critical workflow or component. The proposal makes its boundaries clear so you know what has and has not been assessed.",{"slug":129,"keywords":130,"type":134,"featured":104,"title":135,"summary":136,"audience":137,"fit":138,"tags":139,"scope":143,"deliverables":147,"faq":152},"secure-code-review",[131,132,133],"security code review","C C++ Java security audit","source code security assessment","code-review","Security code review","Find where a vulnerability starts in your code, what it can reach and the smallest change that fixes it.","For technical leads, product owners and teams changing sensitive functionality, inheriting a codebase or investigating a known finding.","When you need root-cause analysis and a practical fix.",[140,141,142],"C \u002F C++","Java","Application code",[144,145,146],"Define the modules, changes, dependencies and relevant data flows.","Review trust boundaries, permissions and handling of untrusted input.","Investigate findings in context and discuss fixes that fit the architecture.",[148,149,150,151],"Code-level findings with affected locations, evidence and impact.","An explanation of the root cause and practical remediation options.","Verification steps and a technical walkthrough for your developers.","The reviewed scope and any limitations in access or validation.",[153,156,159,162],{"question":154,"answer":155},"Which languages and stacks do you review?","I work with application code including C, C++ and Java, alongside a development background in PHP\u002FLaravel, Vue, Node.js and MySQL. Share your stack and review goals so we can confirm the right scope.",{"question":157,"answer":158},"Do you need the entire codebase?","Access depends on the question. A focused review may still need surrounding code, build information or tests to understand permissions, dependencies and data flow.",{"question":160,"answer":161},"Can the review focus on a proposed fix?","Yes. We can examine whether an agreed change addresses the original cause and whether it introduces related issues. Implementation work is agreed separately where needed.",{"question":163,"answer":164},"Can we begin with one component?","Yes. A bounded review of a critical feature, module or change can be a useful first engagement. The report states those boundaries explicitly.",{"slug":166,"keywords":167,"type":166,"featured":104,"title":171,"summary":172,"audience":173,"fit":174,"tags":175,"scope":179,"deliverables":183,"faq":188},"fuzzing",[168,169,170],"targeted fuzzing","C C++ fuzz testing","parser security testing","Targeted fuzzing","Exercise selected components with unexpected inputs, investigate failures and identify security-relevant weaknesses. Start with a target that matters to your product.","For teams building parsers, libraries, SDKs, protocols or application components that process untrusted input.","When malformed files, messages or inputs could expose a weakness.",[176,177,178],"Components & libraries","Unexpected inputs","Failure investigation",[180,181,182],"Assess target feasibility, build requirements, entry points and test objectives.","Set up and run the agreed testing approach for the selected component.","Investigate and deduplicate failures, minimize useful examples and assess security relevance.",[184,185,186,187],"A feasibility assessment and an agreed campaign scope.","Investigated failures with reproducible examples and security analysis.","Setup documentation and agreed testing artifacts your team can retain.","A findings walkthrough, fix guidance and recommendations for continued testing.",[189,192,195,198],{"question":190,"answer":191},"What makes a useful fuzzing target?","A component with clear input boundaries and a build or execution environment we can exercise. Parsers, libraries and protocol handlers are useful candidates. We confirm suitability before committing to a campaign.",{"question":193,"answer":194},"Can we start with a small pilot?","Yes. A paid feasibility phase can establish whether the target is practical, what setup it needs and what a larger campaign should include.",{"question":196,"answer":197},"Will you deliver a harness or ongoing test setup?","We agree the artifacts during scoping. Depending on the target, these may include a harness, seed inputs, run instructions, reproducers or integration guidance. They are specified in the proposal.",{"question":199,"answer":200},"Does every crash mean a vulnerability?","No. Failures need investigation. The report distinguishes observed behavior, confirmed security impact and unresolved questions; it does not promise a number of vulnerabilities or CVEs.",{"slug":202,"keywords":203,"type":207,"featured":104,"title":208,"summary":209,"audience":210,"fit":211,"tags":212,"scope":216,"deliverables":220,"faq":225},"remediation-verification",[204,205,206],"security remediation","vulnerability fix verification","pentest retesting","remediation","Remediation & fix verification","Already have a pentest report? I help your team prioritize the findings, fix them and check that the fixes hold.","For product and engineering teams acting on an assessment, vulnerability report or important security change.","When you have findings and need a clear path to closing them.",[213,214,215],"Fix priorities","Developer guidance","Retesting",[217,218,219],"Review the original evidence, affected version and proposed changes.","Discuss root causes, remediation options and priorities with the responsible team.","Verify agreed fixes against the original issue and relevant related behavior.",[221,222,223,224],"A practical remediation plan for the agreed findings.","Technical guidance tied to the affected component or workflow.","Verification results explaining what was tested and any remaining issues.","A clear record of unresolved questions and next steps.",[226,229,232],{"question":227,"answer":228},"Can you work with a report from another assessor?","Yes, subject to access and sufficient evidence. We first establish what the original findings show and what needs reproduction, clarification or verification.",{"question":230,"answer":231},"Will you implement the fixes?","Developer consultation and verification can be scoped independently. Any implementation or patch work requires its own agreed responsibility, access and acceptance criteria.",{"question":233,"answer":234},"Does a successful retest mean the whole product is secure?","It establishes the result of the agreed checks on the tested version. The verification report identifies its scope and does not substitute for an assessment of unrelated areas.",{"slug":236,"keywords":237,"type":241,"title":242,"summary":243,"audience":244,"fit":245,"tags":246,"scope":250,"deliverables":254,"faq":258},"web-application-security-assessment",[238,239,240],"web application security assessment","API penetration testing","authorization testing","web-assessment","Web & API penetration testing","Can one customer read another customer’s data? I test authentication, roles, tenant isolation and the business logic that scanners cannot model.","For owners and developers of web products, SaaS platforms and APIs preparing a release, changing a sensitive feature or responding to a customer security request.","Before shipping a sensitive web feature or opening an API to customers.",[247,248,249],"Authentication","Authorization","Business logic",[251,252,253],"Agree the application, API endpoints, environments, accounts and testing boundaries.","Review authentication, authorization, input handling and relevant business logic.","Validate attack paths and their impact within the agreed scope.",[255,256,257],"Confirmed findings with evidence, reproduction steps and severity rationale.","Fix guidance connected to the affected feature or code.","A technical walkthrough of priorities, limitations and next steps.",[259,262,265],{"question":260,"answer":261},"Can the assessment include APIs?","Yes. Specify the API, available documentation, account roles and related application workflows. We agree the endpoints and relevant integrations in scope.",{"question":263,"answer":264},"Can you assess a production application?","The environment, permitted actions and operational limits are agreed first. Share availability requirements and other constraints when discussing scope.",{"question":266,"answer":267},"Can you check business logic and permissions?","Yes, where the agreed access and scope support it. Product rules, account roles and sensitive workflows help define useful tests.",{"slug":269,"keywords":270,"type":274,"title":275,"summary":276,"audience":277,"fit":278,"tags":279,"scope":283,"deliverables":287,"faq":291},"mobile-application-security-assessment",[271,272,273],"mobile application security assessment","mobile application penetration testing","mobile API security","mobile-assessment","Mobile application security assessment","Examine security weaknesses in your mobile product and the way it handles data and interacts with its backend. Agree the client and API boundaries before testing.","For mobile product owners and development teams preparing a release, introducing sensitive data flows or arranging an independent customer assessment.","Before a mobile release or a change to sensitive data handling.",[280,281,282],"Mobile client","Local data","Backend boundaries",[284,285,286],"Confirm the platform, application build, access and backend services in scope.","Examine relevant data handling, trust boundaries and client-server interactions.","Validate findings and distinguish client-side issues from backend risks.",[288,289,290],"Confirmed findings with affected components, evidence and reproduction steps.","Practical guidance for the mobile and backend developers responsible for fixes.","An explanation of tested areas, platform constraints and remaining questions.",[292,295,298],{"question":293,"answer":294},"Which mobile platforms can you assess?","Share the platform, framework and build requirements. We confirm suitability and the testing approach before agreeing the engagement; the proposal names the supported targets.",{"question":296,"answer":297},"Is backend and API testing included?","Only when it is explicitly in scope. A mobile application assessment and a backend assessment have connected but different boundaries, which the proposal makes clear.",{"question":299,"answer":300},"What access do you need?","This depends on the agreed approach. Relevant builds, test accounts, environment details and, for code-assisted work, selected source code may be needed.",{"slug":302,"keywords":303,"type":307,"title":308,"summary":309,"audience":310,"fit":311,"tags":312,"scope":314,"deliverables":318,"faq":322},"desktop-application-security-assessment",[304,305,306],"desktop application security assessment","native application pentest","C C++ Java application security","desktop-assessment","Desktop & native application security","Investigate risks in desktop applications, libraries and native components. Review the code and input paths where a defect could become a security problem.","For desktop software, library, SDK and developer-tool vendors working with C, C++ or Java and components that handle untrusted input.","When introducing a parser, protocol, library or important native component.",[140,141,313],"Libraries & input paths",[315,316,317],"Define target components, operating environment, build requirements and trust boundaries.","Examine relevant code, input processing and application behavior.","Use code review, dynamic testing or targeted fuzzing as agreed for the target.",[319,320,321],"Findings connected to affected code or behavior, with reproducible evidence.","Root-cause analysis and remediation guidance for the responsible developers.","Documented testing boundaries, setup limitations and agreed follow-up steps.",[323,326,329],{"question":324,"answer":325},"What kinds of desktop projects are relevant?","Applications, libraries and components with clear security questions, especially around untrusted input. Share the language, operating system and build requirements so we can confirm fit.",{"question":327,"answer":328},"Is fuzzing part of the assessment?","It can be included when suitable for the target. We agree the feasibility work, campaign and artifacts separately rather than assuming every application needs the same approach.",{"question":330,"answer":331},"What public work supports this offer?","My public work includes CVE-2024-26855 and CVE-2025-37858 in the Linux kernel, with fixes accepted upstream. Those records show specific native-code investigation and remediation work.",{"slug":333,"keywords":334,"type":339,"title":340,"summary":341,"audience":342,"fit":343,"tags":344,"scope":347,"deliverables":352,"faq":356},"ai-built-app-security-review",[335,336,337,338],"AI-built app security review","vibe coding security audit","Supabase RLS security check","Lovable app security","ai-app-review","Security review for AI-built apps","Built your app with Cursor, Lovable, Bolt or Copilot? I check the authentication, data access and API keys that AI-generated code often gets wrong, before real users and real data arrive.","For founders, solo builders and small teams who shipped quickly with AI coding tools and now need to know whether one user can reach another user’s data.","Before launch, before taking payments or before onboarding your first business customers.",[247,345,346],"Data access & RLS","Secrets & API keys",[348,349,350,351],"Review sign-up, login, sessions and password reset.","Check who can read and change whose data, including row-level and object-level rules in Supabase, Firebase or your own API.","Look for secrets and API keys exposed in the client, the repository or public storage.","Test payment, webhook and admin flows that trust the client too much.",[353,354,355],"A fix list in order of risk, with evidence for each issue.","The exact code, configuration or prompt change for each fix.","A short call to walk through the results.",[357,360,363],{"question":358,"answer":359},"Is this the same as an automated scan?","No. Scanners and AI review tools catch common patterns. I test the app the way an attacker would: I sign up, switch between accounts and try to reach data that is not mine.",{"question":361,"answer":362},"What do you need from me?","The app URL, two test accounts with different roles and, if possible, read access to the repository and backend settings. Please do not send production passwords by email.",{"question":364,"answer":365},"Which stacks do you cover?","Apps built with tools such as Cursor, Lovable, Bolt, Replit, v0 or Copilot, typically on Next.js, React, Supabase, Firebase or a Node.js API. Tell me your stack and I will confirm the fit.",{"slug":367,"keywords":368,"type":372,"title":373,"summary":374,"audience":375,"fit":376,"tags":377,"scope":381,"deliverables":386,"faq":391},"appsec-tooling-dast-advisory",[369,370,371],"security tool development","SAST DAST engineering","custom vulnerability scanner development","tooling-advisory","Security tool development & SAST\u002FDAST engineering","I build and extend SAST and DAST tools, and evaluate whether the scanner you use finds what matters in your stack. Architecture, detection components and evaluation are tied to your actual targets.","For security product teams and engineering organizations building analysis capabilities, extending scanners or evaluating the quality of their security testing tools.","When you need to build, extend or evaluate a security analysis capability.",[378,379,380],"SAST development","DAST engineering","Detection & evaluation",[382,383,384,385],"Define the analysis goal, target technologies, access, constraints and acceptance criteria.","Design the agreed architecture or implement and extend selected analysis, detection or scanning components.","Evaluate the agreed capabilities against representative targets, documenting coverage, findings and limitations.","Plan integration and handoff around the team’s workflow and maintenance needs.",[387,388,389,390],"A scoped engineering plan with architecture decisions and acceptance criteria.","Agreed designs or implemented components, with tests and technical documentation.","A reproducible evaluation method and results for the agreed targets.","A technical handoff covering integration, limitations and further development.",[392,395,398,401,404],{"question":393,"answer":394},"Do you develop security tools?","Yes. I design and develop SAST and DAST applications. An engagement can cover architecture, selected detection components, extensions, integration or evaluation. The proposal defines the target technologies and what will be delivered.",{"question":396,"answer":397},"What have you built?","Hendra is my modular, context-aware DAST scanner developed during completed doctoral research at ITMO University. I designed its core architecture, technology identification, scan planning, request deduplication, finding review and benchmarking approach.",{"question":399,"answer":400},"Can you extend an existing tool?","Yes, where its architecture, access and licensing permit the agreed work. We first establish the extension points, required behavior and tests for the target capability.",{"question":402,"answer":403},"Which languages can a SAST project cover?","Language coverage is defined for each project. We review the target language, available analysis infrastructure, code patterns and evaluation cases before agreeing development. Coverage and limitations are documented.",{"question":405,"answer":406},"Can you evaluate a tool before we invest in development?","Yes. A scoped evaluation can examine detection behavior, useful coverage, triage effort and integration constraints. Published lab benchmarks provide context; the evaluation needs targets and criteria relevant to your team.",{"slug":408,"type":409,"title":410,"summary":411,"audience":412,"fit":413,"keywords":414,"tags":422,"scope":426,"deliverables":431,"faq":436},"secure-software-engineering","software-engineering","Custom software & website development","Bring your idea to life: a portfolio, a business website, an application or a complete system. I design the architecture, develop the product and connect the services it needs, with clear milestones and a practical handoff.","For individuals, business owners, founders and teams creating websites, portfolios, web, mobile or desktop applications, business systems, APIs and integrations—or improving an existing product.","From a personal portfolio to a complex business platform. The project defines the technology and scope.",[415,416,417,418,419,420,421],"freelance software developer","custom application development","website development","portfolio website developer","business system development","web mobile desktop applications","software architecture",[423,424,425],"Systems & applications","Websites & portfolios","Architecture",[427,428,429,430],"Define users, workflows, constraints, integrations and acceptance criteria.","Plan interfaces, architecture, data flows and integrations, with security appropriate to the product.","Design and implement agreed components in reviewable milestones.","Test the agreed behavior and document deployment, operation and handoff.",[432,433,434,435],"A project plan and architecture appropriate to your product.","Agreed source code, tests and integration artifacts.","Milestone demonstrations against agreed acceptance criteria.","Documentation and a technical handoff for your team.",[437,440,443,446],{"question":438,"answer":439},"What can you develop?","Websites, portfolios, web, mobile and desktop applications, business systems, APIs and integrations. The engagement can cover architecture, implementation or both. We agree the technology, functionality and what a successful delivery looks like before starting.",{"question":441,"answer":442},"Can you join an existing project?","Yes. A focused first phase can examine the codebase, architecture and immediate blockers before committing to implementation milestones. It can also cover one critical component.",{"question":444,"answer":445},"Is an independent security assessment included?","Development includes the agreed security requirements and tests. A separately scoped assessment can examine additional attack paths and provides its own report; its boundaries are agreed explicitly.",{"question":447,"answer":448},"How do we control scope and budget?","Start with a defined discovery or implementation phase. Agree deliverables, acceptance criteria, price and schedule before work, and review proposed changes before adding them to the project.",[450,454,457,460,463,466],{"question":451,"answer":452,"assessmentOnly":453},"How quickly will you reply?","Within three days at most. You get questions about your product or an outline of the proposal.",false,{"question":455,"answer":456,"assessmentOnly":453},"What does it cost?","Published prices are starting points. The final price depends on scope and technical complexity and is fixed in the written proposal before work starts.",{"question":458,"answer":459,"assessmentOnly":453},"How long does it take, and when can you start?","Duration and start date depend on the scope, the technical complexity and my current workload. The proposal states the dates.",{"question":461,"answer":462,"assessmentOnly":453},"Can we work under an NDA?","Yes. Confidentiality terms, including an NDA if you need one, are agreed as part of the proposal before you share code, credentials or findings.",{"question":464,"answer":465,"assessmentOnly":104},"Is a retest included?","Retesting is agreed for each engagement in the proposal: which findings, which version and the time window.",{"question":467,"answer":468,"assessmentOnly":104},"Do you work with agencies?","Yes. Agencies can bring me in for a client’s project. Delivery terms, including white-label reports, are agreed case by case in the proposal.",{"title":470,"steps":471},"How an engagement runs",[472,475,478,481],{"title":473,"body":474},"Send a short brief","The product, what changed, what you need to know and by when. A paragraph is enough, and I reply within three days.",{"title":476,"body":477},"Get a written proposal","Scope, method, exclusions, deliverables, price and dates. Confidentiality, NDA and retesting terms are agreed in the same proposal.",{"title":479,"body":480},"Follow the work as it develops","For assessments, you see evidence and priorities as they emerge. For engineering, you review the agreed milestones.",{"title":482,"body":483},"Report and walkthrough","You receive the report or the delivered work and a walkthrough with your team. Any further fixes or verification are agreed with you.",{"title":485,"lead":486,"paragraphs":487},"I find vulnerabilities, and I write the fixes.","I’m Rand Deeb, a lead application security engineer and independent security researcher. I have reported 150+ security vulnerabilities, wrote the fixes for two Linux kernel CVEs and built the Hendra DAST scanner. I test web apps and APIs for product teams and do the work myself.",[488,489,490,491,492,493],"My full-stack development background helps me understand how a feature is built and how a fix will affect the rest of the application. I combine that perspective with security testing, code review and vulnerability research.","I also design and develop security applications for static analysis (SAST) and dynamic testing (DAST). This work connects software architecture, detection logic and reproducible evaluation, experience I can apply to a scoped tool development or extension project.","At Confident, my engineering work spans SAST, DAST, C++ and security engineering. Previously, I worked in web development and web security at Momento.","Meta has validated and acknowledged seven security vulnerabilities I reported in Facebook and Instagram. In Linux kernel code, I have triaged more than 300 static-analysis reports and contributed nine patches. My work also includes two published CVEs, CVE-2024-26855 and CVE-2025-37858, with fixes accepted into mainline Linux. The ice driver fix was backported to stable trees. The CVE records and linked fixes are available for you to inspect.","Hendra is a concrete example: a modular, context-aware DAST scanner I developed during my completed doctoral research project at ITMO University. I designed its core architecture and the components for technology identification, scan planning, request deduplication, finding review and benchmarking. My publications examine the methods behind this work.","If you are preparing a release or answering a customer’s security review, send me a short brief.",{"title":25,"lead":495,"labels":496,"types":514},"Tell me what you are shipping, what you need to know and by when. I reply within three days with questions or a proposal outline. If you need an NDA before sharing details, say so.",{"name":497,"email":498,"company":499,"type":500,"message":501,"consent":502,"source":503,"submit":25,"sending":504,"success":505,"successBody":506,"successArticle":507,"error":508,"privacyNote":509,"scopeNote":510,"unavailable":511,"emailInstead":512,"retry":513},"Name","Email","Company or team (optional)","What do you need?","What should I test, and why now?","I agree to the processing of my enquiry and contact details as described in the privacy notice.","How did you hear about me? (optional)","Sending…","Thank you. Your request has reached me.","I will reply to the email address you gave within three days. Meanwhile, you can check my track record or read how to choose between a pentest and a code review.","Pentest or code review: which do you need?","Your enquiry could not be sent. Please try again or use an available contact channel.","Rand Deeb, based in Russia, uses your details to reply and discuss your project. The form sends your message by email. If no project follows, correspondence is deleted 12 months after our last contact. See the privacy notice for your rights.","Keep secrets out of this form: passwords, tokens, source code and unreleased findings can follow later, under an NDA if you need one.","The form is temporarily unavailable. Please email your project details directly.","Send your enquiry by email","Try the form again",[515,516,517,519,521,523,524,525,527,529,532,534,537],{"value":103,"label":105},{"value":241,"label":242},{"value":274,"label":518},"Mobile application assessment",{"value":307,"label":520},"Desktop \u002F native assessment",{"value":339,"label":522},"Security review for an AI-built app",{"value":134,"label":135},{"value":166,"label":171},{"value":207,"label":526},"Remediation \u002F fix verification",{"value":372,"label":528},"Security tool development \u002F SAST & DAST",{"value":530,"label":531},"agency","Agency or partner project",{"value":409,"label":533},"Software \u002F website \u002F portfolio development",{"value":535,"label":536},"other","Help me choose \u002F other enquiry",{"value":538,"label":16},"roles-research",{"title":540,"lead":541,"updatedLabel":542,"updatedDate":543,"contentsLabel":544,"contactLabel":545,"sections":546},"Privacy notice","How I handle your enquiry, the information collected when you visit this site, and your choices.","Last updated","7 October 2026","On this page","Contact me about your data",[547,554,562,576,590,597,605,612,626],{"id":548,"title":549,"paragraphs":550,"links":553},"operator","Who is responsible",[551,552],"I am Rand Deeb, an independent software engineer and security specialist based in Russia. I operate rand-deeb.com and am responsible for the personal information I use to handle enquiries through this website.","For a privacy question or a request about your information, email contact@rand-deeb.com. This notice covers the website and initial enquiries. A client project may require a separate agreement covering confidential material and project data.",[],{"id":555,"title":556,"paragraphs":557,"links":561},"enquiries","When you contact me",[558,559,560],"The form collects your name, email address, selected service, message, language and confirmation that you agree to the processing of your enquiry. Your company or team name and your answer to “How did you hear about me?” are optional. With the enquiry, the form also sends the first page you opened on this site, including any campaign tags in its address, and the domain of the website that linked you here. Your browser keeps these two details in session storage until you close the tab; they are not sent anywhere unless you submit the form. I use these details to understand your request, see which pages and links bring enquiries, discuss scope and pricing, and reply to you.","You choose whether to contact me. The required fields let me handle a form submission; without them, the form cannot be sent. You can use the email link instead. Sending an enquiry does not subscribe you to a mailing list.","Keep the first message to a short description of your project. Do not send passwords, access tokens, confidential source code or undisclosed vulnerability details. We can arrange an NDA and a suitable exchange channel before sharing sensitive material.",[],{"id":563,"title":564,"paragraphs":565,"links":569},"hosting","Hosting, email and other services",[566,567,568],"The Vercel-hosted website processes your connection to serve pages and receive form submissions. Technical information includes your IP address, requested page, request time, and browser or device information. It is used to operate the site, diagnose problems and protect it against abuse.","Successful form submissions are forwarded to my inbox through email delivery. Email providers process the message to deliver and store it. The website does not keep a separate database of enquiry messages. Hosting and email services may process information outside your country, including outside Russia and the European Economic Area.","Telegram, LinkedIn and other external links take you to separate services. They receive information when you use them and have their own privacy terms. The contact form does not automatically send your message to Telegram. The interview recording and conference photos are served by this website rather than an embedded social-media player.",[570,573],{"label":571,"href":572},"Vercel privacy notice","https:\u002F\u002Fvercel.com\u002Flegal\u002Fprivacy-notice",{"label":574,"href":575},"Telegram privacy policy","https:\u002F\u002Ftelegram.org\u002Fprivacy",{"id":577,"title":578,"paragraphs":579,"links":583},"measurement","Visitor counts and performance",[580,581,582],"On Vercel, Web Analytics measures visits and page views, and Speed Insights measures loading speed, visual stability and responsiveness. Reports help me see which content is useful and where the website needs improvement.","The measurements include page addresses, referrers, browser and device information, approximate location and performance timings. Speed Insights also receives connection information and diagnostic details about page elements. Vercel describes these reports as aggregate or anonymous; Web Analytics does not use analytics cookies.","The form fields and message are not sent as custom analytics events. I do not use advertising pixels, session recordings or automated decisions about whether to work with a client. Browser content blockers can prevent the measurement scripts from loading.",[584,587],{"label":585,"href":586},"Vercel Web Analytics: data collected","https:\u002F\u002Fvercel.com\u002Fdocs\u002Fanalytics\u002Fprivacy-policy",{"label":588,"href":589},"Vercel Speed Insights: data collected","https:\u002F\u002Fvercel.com\u002Fdocs\u002Fspeed-insights\u002Fprivacy-policy",{"id":591,"title":592,"paragraphs":593,"links":596},"language","Your language preference",[594,595],"The cookie named i18n_redirected remembers your chosen language for up to one year. On your first visit to the homepage, a supported browser language is used; otherwise the site opens in English. You can switch languages at any time.","This cookie is for language selection, not visitor tracking. You can remove it through your browser settings. The website uses locally hosted fonts; reading a page does not require a request to Google Fonts.",[],{"id":598,"title":599,"paragraphs":600,"links":604},"retention","How long I keep information",[601,602,603],"If an enquiry does not become a project, I delete the correspondence from my active inbox 12 months after our last contact. This is an inbox-cleanup policy; the website does not automatically delete email.","If we work together, project correspondence and contractual records are kept for the project and any applicable record-keeping or legal-claim requirements. Hosting logs, measurement reports and email-provider backups follow the relevant provider’s retention settings. Deleting an inbox message does not immediately remove every provider backup.","You can ask for deletion before the 12 months are up. If I need to retain particular information for a legal obligation or an active claim, I will explain what needs to be kept and why.",[],{"id":606,"title":607,"paragraphs":608,"links":611},"rights","Access, correction and deletion",[609,610],"Email contact@rand-deeb.com to ask what information I hold about you, correct it, request its deletion, or withdraw consent to processing based on your consent. If you want me to stop following up on an enquiry, say so in your message.","Depending on the law that applies, you may also have rights to restrict processing, object to it or receive your information in a portable format. I may ask for enough information to verify the request without collecting unnecessary identity documents. Withdrawing consent does not undo processing that was lawful before withdrawal.",[],{"id":613,"title":614,"paragraphs":615,"links":619},"regional-rights","Rights in your location",[616,617,618],"Russia: where Federal Law No. 152-FZ applies, you can request information about the processing of your personal data and seek correction, blocking or deletion in the circumstances provided by that law. You can raise a concern with Roskomnadzor or seek a judicial remedy.","EU and EEA: where the GDPR applies, requested project discussions rely on steps taken at your request before entering a contract; general correspondence and site security rely on the legitimate interests of responding to enquiries and operating a secure website. Processing that requires consent must have that consent. You have the applicable GDPR rights and can complain to the supervisory authority in your country. GDPR requests are normally answered within one month, with an extension where the regulation permits it.","Your location and the circumstances of the processing determine which rights and rules apply. Choosing English, Russian, Arabic or German does not change this. Visitors elsewhere can contact me about their information and any rights under their local law.",[620,623],{"label":621,"href":622},"Roskomnadzor personal-data portal","https:\u002F\u002Fpd.rkn.gov.ru\u002F",{"label":624,"href":625},"European data-protection authorities","https:\u002F\u002Fwww.edpb.europa.eu\u002Fabout-edpb\u002Fabout-edpb\u002Fmembers_en",{"id":627,"title":628,"paragraphs":629,"links":631},"changes","Changes to this notice",[630],"I update this notice when the website’s data handling changes. The date above identifies this version. Before using enquiry information for a different purpose, I will provide the information and obtain any consent required for that use.",[],{"title":633,"body":634,"label":25},"Shipping something that handles user data?","Send me a short brief. I reply within three days with questions or a proposal outline, and the price is agreed in writing before work starts.",1791388004786]