[{"data":1,"prerenderedAt":585},["ShallowReactive",2],{"site-content:en":3},{"nav":4,"hero":18,"headings":35,"intro":42,"blog":43,"reasonsToHire":62,"coverage":81,"services":96,"process":424,"about":439,"contact":449,"privacy":489,"cta":582},{"services":5,"research":6,"blog":7,"about":8,"contact":9,"menu":10,"close":11,"skip":12,"language":13,"home":14,"privacy":15,"roles":16,"serviceDetails":17},"Services","Research","Blog","About","Contact","Menu","Close","Skip to content","Choose language","Home","Privacy","Roles & research collaboration","View service",{"eyebrow":19,"lines":20,"lead":24,"primary":25,"secondary":26,"readout":27},"Rand Deeb · Lead software engineer & security researcher",[21,22,23],"Find vulnerabilities","before they become","\u003Cem>costly incidents.\u003C\u002Fem>","I build systems, applications, websites and portfolios—and uncover exploitable weaknesses. My software-engineering education and doctoral security research connect how products are built with how they can break. Bring me your idea or existing product.","Discuss your project","Explore my work",{"title":28,"items":29,"note":34},"The work behind the promise",[30,31,32,33],"150+ bugs reported across applications","7 Meta acknowledgments · Facebook & Instagram","8 Linux kernel patches · 2 published CVEs","Hendra creator · SAST & DAST engineering","Work directly with me. Scope, price and deliverables agreed before we start.",{"evidence":36,"expertise":37,"work":38,"research":39,"experience":40,"contact":9,"process":41},"Expertise you can verify","Choose the work your product needs","Public work behind the expertise","Security tools & research","Engineering & security experience","From your first question to a useful result","Build a website, portfolio, application or business system. Test a release, review code or develop a security tool. Choose a defined engagement with clear outputs and direct access to the engineer doing the work.",{"title":44,"lead":45,"latest":46,"readArticle":47,"allArticles":48,"all":49,"categories":50,"published":54,"updated":55,"author":56,"sources":57,"contents":58,"relatedService":59,"empty":60,"titleLatest":61},"Application security blog","CVE explainers, code review patterns and practical guidance for people who build and own software.","Latest articles","Read article","All articles","All",{"cve":51,"guides":52,"news":53},"CVE explainers","Practical guides","Security news","Published","Updated","Author","Sources","In this article","Discuss this kind of review","No articles in this category yet.","Useful lessons from security research",{"title":63,"lead":64,"items":65},"Research depth. Engineering judgment. Personal ownership.","You need someone who understands the system, investigates the difficult parts and gives your team a useful way forward.",[66,71,76],{"title":67,"body":68,"evidence":69,"href":70},"I investigate down to the cause.","Facebook and Instagram research, 300+ Linux kernel reports and findings investigated, eight patches and two published CVEs. I connect a suspicious behavior to the code, the conditions that trigger it and the impact on your product.","See the kernel findings and fixes","\u002Fresearch\u002Fcve-2024-26855",{"title":72,"body":73,"evidence":74,"href":75},"I can build the system behind the solution.","My work spans software architecture, implementation and security research. I designed and developed Hendra’s context-aware scanning architecture. That experience is useful when your challenge needs engineering as well as investigation.","See how I built Hendra","\u002Fresearch\u002Fhendra",{"title":77,"body":78,"evidence":79,"href":80},"You get the person doing the work.","I discuss the scope with you, carry out the agreed work and walk your team through the result. Expect reproducible evidence, clear technical decisions and a handoff your developers can use.","Tell me about your project","\u002Fcontact",{"title":82,"items":83},"Web, mobile and desktop. The product sets the scope.",[84,88,92],{"title":85,"body":86,"href":87},"Web & APIs","Authentication, permissions, sensitive workflows and the application behind your API. My strongest and preferred area of practice.","\u002Fservices\u002Fweb-application-security-assessment",{"title":89,"body":90,"href":91},"Mobile applications","The application, its local data and its connection to backend services—with the platform and API boundaries agreed explicitly.","\u002Fservices\u002Fmobile-application-security-assessment",{"title":93,"body":94,"href":95},"Desktop & native software","Application code, libraries and components handling untrusted input. C, C++ and Java projects scoped around the risks that matter.","\u002Fservices\u002Fdesktop-application-security-assessment",[97,134,171,207,241,277,310,341,382],{"slug":98,"keywords":99,"type":103,"featured":104,"title":105,"summary":106,"audience":107,"fit":108,"tags":109,"scope":112,"deliverables":116,"faq":121},"application-penetration-testing",[100,101,102],"application penetration testing","freelance pentester","web mobile desktop pentest","application-pentest",true,"Application penetration testing","Find out how weaknesses in your web, mobile or desktop application could affect your users, data and business. Receive confirmed findings and clear priorities for fixing them.","For product owners, CTOs and development teams preparing a release, responding to a customer assessment request or checking an existing product.","Before a release, customer review or important product change.",[85,110,111],"Mobile","Desktop",[113,114,115],"Define the product, versions, environments, access and permitted testing.","Investigate relevant attack paths, trust boundaries and security-sensitive functionality.","Validate findings and explain their impact within the agreed scope.",[117,118,119,120],"An assessment report with confirmed findings, evidence and reproduction steps.","Priorities grounded in the affected product and the impact of each finding.","Practical fix guidance and a walkthrough with your technical team.","A record of tested areas, scope limitations and agreed next steps.",[122,125,128,131],{"question":123,"answer":124},"Can you test web, mobile and desktop applications?","Yes. Share the product, platform and goal. We will define the targets, methods and access appropriate to your application. Web and API security are my strongest and preferred area of practice.",{"question":126,"answer":127},"What if we only need one feature checked?","We can scope a focused review of a critical workflow or component. The proposal makes its boundaries clear so you know what has and has not been assessed.",{"question":129,"answer":130},"How do you determine price and timing?","From the targets, complexity, access, depth and required deliverables. You receive an agreed scope, price and schedule before testing begins.",{"question":132,"answer":133},"Is fix verification included?","We agree any retesting allowance in the proposal, including the findings, version and time window. Further remediation or verification can also be a separate engagement.",{"slug":135,"keywords":136,"type":140,"featured":104,"title":141,"summary":142,"audience":143,"fit":144,"tags":145,"scope":149,"deliverables":153,"faq":158},"secure-code-review",[137,138,139],"security code review","C C++ Java security audit","source code security assessment","code-review","Security code review","Examine the code behind your most important features. Understand where a weakness begins, what it affects and how your developers can address it.","For technical leads, product owners and teams changing sensitive functionality, inheriting a codebase or investigating a known finding.","When you need root-cause analysis and a practical fix.",[146,147,148],"C \u002F C++","Java","Application code",[150,151,152],"Define the modules, changes, dependencies and relevant data flows.","Review trust boundaries, permissions and handling of untrusted input.","Investigate findings in context and discuss fixes that fit the architecture.",[154,155,156,157],"Code-level findings with affected locations, evidence and impact.","An explanation of the root cause and practical remediation options.","Verification steps and a technical walkthrough for your developers.","The reviewed scope and any limitations in access or validation.",[159,162,165,168],{"question":160,"answer":161},"Which languages and stacks do you review?","I work with application code including C, C++ and Java, alongside a development background in PHP\u002FLaravel, Vue, Node.js and MySQL. Share your stack and review goals so we can confirm the right scope.",{"question":163,"answer":164},"Do you need the entire codebase?","Access depends on the question. A focused review may still need surrounding code, build information or tests to understand permissions, dependencies and data flow.",{"question":166,"answer":167},"Can the review focus on a proposed fix?","Yes. We can examine whether an agreed change addresses the original cause and whether it introduces related issues. Implementation work is agreed separately where needed.",{"question":169,"answer":170},"Can we begin with one component?","Yes. A bounded review of a critical feature, module or change can be a useful first engagement. The report states those boundaries explicitly.",{"slug":172,"keywords":173,"type":172,"featured":104,"title":177,"summary":178,"audience":179,"fit":180,"tags":181,"scope":185,"deliverables":189,"faq":194},"fuzzing",[174,175,176],"targeted fuzzing","C C++ fuzz testing","parser security testing","Targeted fuzzing","Exercise selected components with unexpected inputs, investigate failures and identify security-relevant weaknesses. Start with a target that matters to your product.","For teams building parsers, libraries, SDKs, protocols or application components that process untrusted input.","When malformed files, messages or inputs could expose a weakness.",[182,183,184],"Components & libraries","Unexpected inputs","Failure investigation",[186,187,188],"Assess target feasibility, build requirements, entry points and test objectives.","Set up and run the agreed testing approach for the selected component.","Investigate and deduplicate failures, minimize useful examples and assess security relevance.",[190,191,192,193],"A feasibility assessment and an agreed campaign scope.","Investigated failures with reproducible examples and security analysis.","Setup documentation and agreed testing artifacts your team can retain.","A findings walkthrough, fix guidance and recommendations for continued testing.",[195,198,201,204],{"question":196,"answer":197},"What makes a useful fuzzing target?","A component with clear input boundaries and a build or execution environment we can exercise. Parsers, libraries and protocol handlers are useful candidates. We confirm suitability before committing to a campaign.",{"question":199,"answer":200},"Can we start with a small pilot?","Yes. A paid feasibility phase can establish whether the target is practical, what setup it needs and what a larger campaign should include.",{"question":202,"answer":203},"Will you deliver a harness or ongoing test setup?","We agree the artifacts during scoping. Depending on the target, these may include a harness, seed inputs, run instructions, reproducers or integration guidance. They are specified in the proposal.",{"question":205,"answer":206},"Does every crash mean a vulnerability?","No. Failures need investigation. The report distinguishes observed behavior, confirmed security impact and unresolved questions; it does not promise a number of vulnerabilities or CVEs.",{"slug":208,"keywords":209,"type":213,"featured":104,"title":214,"summary":215,"audience":216,"fit":217,"tags":218,"scope":222,"deliverables":226,"faq":231},"remediation-verification",[210,211,212],"security remediation","vulnerability fix verification","pentest retesting","remediation","Remediation & fix verification","Turn security findings into engineering decisions. Prioritize the work, discuss fixes with your developers and check whether agreed changes address the issue.","For product and engineering teams acting on an assessment, vulnerability report or important security change.","When you have findings and need a clear path to closing them.",[219,220,221],"Fix priorities","Developer guidance","Retesting",[223,224,225],"Review the original evidence, affected version and proposed changes.","Discuss root causes, remediation options and priorities with the responsible team.","Verify agreed fixes against the original issue and relevant related behavior.",[227,228,229,230],"A practical remediation plan for the agreed findings.","Technical guidance tied to the affected component or workflow.","Verification results explaining what was tested and any remaining issues.","A clear record of unresolved questions and next steps.",[232,235,238],{"question":233,"answer":234},"Can you work with a report from another assessor?","Yes, subject to access and sufficient evidence. We first establish what the original findings show and what needs reproduction, clarification or verification.",{"question":236,"answer":237},"Will you implement the fixes?","Developer consultation and verification can be scoped independently. Any implementation or patch work requires its own agreed responsibility, access and acceptance criteria.",{"question":239,"answer":240},"Does a successful retest mean the whole product is secure?","It establishes the result of the agreed checks on the tested version. The verification report identifies its scope and does not substitute for an assessment of unrelated areas.",{"slug":242,"keywords":243,"type":247,"title":248,"summary":249,"audience":250,"fit":251,"tags":252,"scope":256,"deliverables":260,"faq":264},"web-application-security-assessment",[244,245,246],"web application security assessment","API penetration testing","authorization testing","web-assessment","Web & API penetration testing","Assess the authentication, permissions and business workflows that protect your users and data. Connect each confirmed finding to a practical next step.","For owners and developers of web products, SaaS platforms and APIs preparing a release, changing a sensitive feature or responding to a customer security request.","Before shipping a sensitive web feature or opening an API to customers.",[253,254,255],"Authentication","Authorization","Business logic",[257,258,259],"Agree the application, API endpoints, environments, accounts and testing boundaries.","Review authentication, authorization, input handling and relevant business logic.","Validate attack paths and their impact within the agreed scope.",[261,262,263],"Confirmed findings with evidence, reproduction steps and severity rationale.","Fix guidance connected to the affected feature or code.","A technical walkthrough of priorities, limitations and next steps.",[265,268,271,274],{"question":266,"answer":267},"Can the assessment include APIs?","Yes. Specify the API, available documentation, account roles and related application workflows. We agree the endpoints and relevant integrations in scope.",{"question":269,"answer":270},"Can you assess a production application?","The environment, permitted actions and operational limits are agreed first. Share availability requirements and other constraints when discussing scope.",{"question":272,"answer":273},"Can you check business logic and permissions?","Yes, where the agreed access and scope support it. Product rules, account roles and sensitive workflows help define useful tests.",{"question":275,"answer":276},"How are timing and price determined?","By the targets, access, complexity, testing depth and deliverables. The written proposal defines scope and terms before testing begins.",{"slug":278,"keywords":279,"type":283,"title":284,"summary":285,"audience":286,"fit":287,"tags":288,"scope":292,"deliverables":296,"faq":300},"mobile-application-security-assessment",[280,281,282],"mobile application security assessment","mobile application penetration testing","mobile API security","mobile-assessment","Mobile application security assessment","Examine security weaknesses in your mobile product and the way it handles data and interacts with its backend. Agree the client and API boundaries before testing.","For mobile product owners and development teams preparing a release, introducing sensitive data flows or arranging an independent customer assessment.","Before a mobile release or a change to sensitive data handling.",[289,290,291],"Mobile client","Local data","Backend boundaries",[293,294,295],"Confirm the platform, application build, access and backend services in scope.","Examine relevant data handling, trust boundaries and client-server interactions.","Validate findings and distinguish client-side issues from backend risks.",[297,298,299],"Confirmed findings with affected components, evidence and reproduction steps.","Practical guidance for the mobile and backend developers responsible for fixes.","An explanation of tested areas, platform constraints and remaining questions.",[301,304,307],{"question":302,"answer":303},"Which mobile platforms can you assess?","Share the platform, framework and build requirements. We confirm suitability and the testing approach before agreeing the engagement; the proposal names the supported targets.",{"question":305,"answer":306},"Is backend and API testing included?","Only when it is explicitly in scope. A mobile application assessment and a backend assessment have connected but different boundaries, which the proposal makes clear.",{"question":308,"answer":309},"What access do you need?","This depends on the agreed approach. Relevant builds, test accounts, environment details and, for code-assisted work, selected source code may be needed.",{"slug":311,"keywords":312,"type":316,"title":317,"summary":318,"audience":319,"fit":320,"tags":321,"scope":323,"deliverables":327,"faq":331},"desktop-application-security-assessment",[313,314,315],"desktop application security assessment","native application pentest","C C++ Java application security","desktop-assessment","Desktop & native application security","Investigate risks in desktop applications, libraries and native components. Review the code and input paths where a defect could become a security problem.","For desktop software, library, SDK and developer-tool vendors working with C, C++ or Java and components that handle untrusted input.","When introducing a parser, protocol, library or important native component.",[146,147,322],"Libraries & input paths",[324,325,326],"Define target components, operating environment, build requirements and trust boundaries.","Examine relevant code, input processing and application behavior.","Use code review, dynamic testing or targeted fuzzing as agreed for the target.",[328,329,330],"Findings connected to affected code or behavior, with reproducible evidence.","Root-cause analysis and remediation guidance for the responsible developers.","Documented testing boundaries, setup limitations and agreed follow-up steps.",[332,335,338],{"question":333,"answer":334},"What kinds of desktop projects are relevant?","Applications, libraries and components with clear security questions, especially around untrusted input. Share the language, operating system and build requirements so we can confirm fit.",{"question":336,"answer":337},"Is fuzzing part of the assessment?","It can be included when suitable for the target. We agree the feasibility work, campaign and artifacts separately rather than assuming every application needs the same approach.",{"question":339,"answer":340},"What public work supports this offer?","My public work includes CVE-2024-26855 and CVE-2025-37858 in the Linux kernel, with fixes accepted upstream. Those records show specific native-code investigation and remediation work.",{"slug":342,"keywords":343,"type":347,"title":348,"summary":349,"audience":350,"fit":351,"tags":352,"scope":356,"deliverables":361,"faq":366},"appsec-tooling-dast-advisory",[344,345,346],"security tool development","SAST DAST engineering","custom vulnerability scanner development","tooling-advisory","Security tool development & SAST\u002FDAST engineering","I design and develop advanced applications for static and dynamic security testing. Define a useful architecture, build agreed detection components or extend an existing tool—with evaluation tied to your actual targets.","For security product teams and engineering organizations building analysis capabilities, extending scanners or evaluating the quality of their security testing tools.","When you need to build, extend or evaluate a security analysis capability.",[353,354,355],"SAST development","DAST engineering","Detection & evaluation",[357,358,359,360],"Define the analysis goal, target technologies, access, constraints and acceptance criteria.","Design the agreed architecture or implement and extend selected analysis, detection or scanning components.","Evaluate the agreed capabilities against representative targets, documenting coverage, findings and limitations.","Plan integration and handoff around the team’s workflow and maintenance needs.",[362,363,364,365],"A scoped engineering plan with architecture decisions and acceptance criteria.","Agreed designs or implemented components, with tests and technical documentation.","A reproducible evaluation method and results for the agreed targets.","A technical handoff covering integration, limitations and further development.",[367,370,373,376,379],{"question":368,"answer":369},"Do you develop security tools?","Yes. I design and develop SAST and DAST applications. An engagement can cover architecture, selected detection components, extensions, integration or evaluation. The proposal defines the target technologies and what will be delivered.",{"question":371,"answer":372},"What have you built?","Hendra is my modular, context-aware DAST scanner developed during completed doctoral research at ITMO University. I designed its core architecture, technology identification, scan planning, request deduplication, finding review and benchmarking approach.",{"question":374,"answer":375},"Can you extend an existing tool?","Yes, where its architecture, access and licensing permit the agreed work. We first establish the extension points, required behavior and tests for the target capability.",{"question":377,"answer":378},"Which languages can a SAST project cover?","Language coverage is defined for each project. We review the target language, available analysis infrastructure, code patterns and evaluation cases before agreeing development. Coverage and limitations are documented.",{"question":380,"answer":381},"Can you evaluate a tool before we invest in development?","Yes. A scoped evaluation can examine detection behavior, useful coverage, triage effort and integration constraints. Published lab benchmarks provide context; the evaluation needs targets and criteria relevant to your team.",{"slug":383,"type":384,"title":385,"summary":386,"audience":387,"fit":388,"keywords":389,"tags":397,"scope":401,"deliverables":406,"faq":411},"secure-software-engineering","software-engineering","Custom software & website development","Bring your idea to life: a portfolio, a business website, an application or a complete system. I design the architecture, develop the product and connect the services it needs, with clear milestones and a practical handoff.","For individuals, business owners, founders and teams creating websites, portfolios, web, mobile or desktop applications, business systems, APIs and integrations—or improving an existing product.","From a personal portfolio to a complex business platform. The project defines the technology and scope.",[390,391,392,393,394,395,396],"freelance software developer","custom application development","website development","portfolio website developer","business system development","web mobile desktop applications","software architecture",[398,399,400],"Systems & applications","Websites & portfolios","Architecture",[402,403,404,405],"Define users, workflows, constraints, integrations and acceptance criteria.","Plan interfaces, architecture, data flows and integrations, with security appropriate to the product.","Design and implement agreed components in reviewable milestones.","Test the agreed behavior and document deployment, operation and handoff.",[407,408,409,410],"A project plan and architecture appropriate to your product.","Agreed source code, tests and integration artifacts.","Milestone demonstrations against agreed acceptance criteria.","Documentation and a technical handoff for your team.",[412,415,418,421],{"question":413,"answer":414},"What can you develop?","Websites, portfolios, web, mobile and desktop applications, business systems, APIs and integrations. The engagement can cover architecture, implementation or both. We agree the technology, functionality and what a successful delivery looks like before starting.",{"question":416,"answer":417},"Can you join an existing project?","Yes. A focused first phase can examine the codebase, architecture and immediate blockers before committing to implementation milestones. It can also cover one critical component.",{"question":419,"answer":420},"Is an independent security assessment included?","Development includes the agreed security requirements and tests. A separately scoped assessment can examine additional attack paths and provides its own report; its boundaries are agreed explicitly.",{"question":422,"answer":423},"How do we control scope and budget?","Start with a defined discovery or implementation phase. Agree deliverables, acceptance criteria, price and schedule before work, and review proposed changes before adding them to the project.",{"title":425,"steps":426},"A clear start. A useful finish.",[427,430,433,436],{"title":428,"body":429},"Tell me the problem","Share the product, stack, goal and deadline. A short overview is enough to start the conversation.",{"title":431,"body":432},"Agree the engagement","Receive a written scope, deliverables, acceptance criteria, price and schedule before we begin.",{"title":434,"body":435},"Review the work as it develops","For assessments, examine the evidence and priorities. For engineering, review agreed implementation milestones.",{"title":437,"body":438},"Put the result to work","Get a technical walkthrough and useful handoff. Agree any further implementation or verification your team needs.",{"title":440,"lead":441,"paragraphs":442},"A developer’s understanding. A researcher’s scrutiny.","I’m Rand Deeb, a lead software engineer and independent security researcher. I develop systems, applications, websites and portfolios—from a personal site to a complex business platform. My security work includes vulnerability research and custom SAST and DAST tools.",[443,444,445,446,447,448],"My full-stack development background helps me understand how a feature is built and how a fix will affect the rest of the application. I combine that perspective with security testing, code review and vulnerability research.","I also design and develop advanced security applications for static analysis (SAST) and dynamic testing (DAST). This work connects software architecture, detection logic and reproducible evaluation—experience I can apply to a scoped tool development or extension project.","At Confident, my engineering work spans SAST, DAST, C++ and security engineering. Previously, I worked in web development and web security at Momento.","My security research has received seven acknowledgments from Meta for Facebook and Instagram findings. In Linux kernel code, I have investigated more than 300 review reports and findings through static analysis and contributed eight patches. My work also includes two published CVEs, CVE-2024-26855 and CVE-2025-37858, with fixes accepted into mainline Linux. The ice driver fix was backported to stable trees. The CVE records and linked fixes are available for you to inspect.","Hendra is a concrete example: a modular, context-aware DAST scanner I developed during my completed doctoral research project at ITMO University. I designed its core architecture and the components for technology identification, scan planning, request deduplication, finding review and benchmarking. My publications examine the methods behind this work.","For your project, the goal is practical: understand the relevant weaknesses, explain the cause and give your team evidence and guidance it can act on.",{"title":450,"lead":451,"labels":452,"types":468},"Let’s discuss your project.","A short overview is enough: what you’re building, the problem you need solved and any relevant deadline. I’ll review the fit and discuss the scope, deliverables and price with you.",{"name":453,"email":454,"company":455,"type":456,"message":457,"consent":458,"submit":459,"sending":460,"success":461,"error":462,"privacyNote":463,"scopeNote":464,"unavailable":465,"emailInstead":466,"retry":467},"Name","Email","Company or team (optional)","What do you need?","Product, stack and goal","I agree to the processing of my enquiry and contact details as described in the privacy notice.","Send project enquiry","Sending…","Your enquiry has been sent.","Your enquiry could not be sent. Please try again or use an available contact channel.","Rand Deeb, based in Russia, uses your details to reply and discuss your project. The form sends your message by email. If no project follows, correspondence is deleted 12 months after our last contact. See the privacy notice for your rights.","Do not send passwords, tokens, source code or sensitive findings here. Mention if an NDA is required before sharing details.","The form is temporarily unavailable. Please email your project details directly.","Send your enquiry by email","Try the form again",[469,470,471,472,474,476,478,480,482,484,486],{"value":103,"label":105},{"value":140,"label":141},{"value":172,"label":177},{"value":213,"label":473},"Remediation \u002F fix verification",{"value":247,"label":475},"Web & API assessment",{"value":283,"label":477},"Mobile application assessment",{"value":316,"label":479},"Desktop \u002F native assessment",{"value":347,"label":481},"Security tool development \u002F SAST & DAST",{"value":384,"label":483},"Software \u002F website \u002F portfolio development",{"value":485,"label":16},"roles-research",{"value":487,"label":488},"other","Help me choose \u002F other enquiry",{"title":490,"lead":491,"updatedLabel":492,"updatedDate":493,"contentsLabel":494,"contactLabel":495,"sections":496},"Privacy notice","How I handle your enquiry, the information collected when you visit this site, and your choices.","Last updated","5 October 2026","On this page","Contact me about your data",[497,504,512,526,540,547,555,562,576],{"id":498,"title":499,"paragraphs":500,"links":503},"operator","Who is responsible",[501,502],"I am Rand Deeb, an independent software engineer and security specialist based in Russia. I operate rand-deeb.com and am responsible for the personal information I use to handle enquiries through this website.","For a privacy question or a request about your information, email contact@rand-deeb.com. This notice covers the website and initial enquiries. A client project may require a separate agreement covering confidential material and project data.",[],{"id":505,"title":506,"paragraphs":507,"links":511},"enquiries","When you contact me",[508,509,510],"The form collects your name, email address, selected service, message, language and confirmation that you agree to the processing of your enquiry. Your company or team name is optional. I use these details to understand your request, discuss scope and pricing, and reply to you.","You choose whether to contact me. The required fields let me handle a form submission; without them, the form cannot be sent. You can use the email link instead. Sending an enquiry does not subscribe you to a mailing list.","Keep the first message to a short description of your project. Do not send passwords, access tokens, confidential source code or undisclosed vulnerability details. We can arrange an NDA and a suitable exchange channel before sharing sensitive material.",[],{"id":513,"title":514,"paragraphs":515,"links":519},"hosting","Hosting, email and other services",[516,517,518],"The Vercel-hosted website processes your connection to serve pages and receive form submissions. Technical information includes your IP address, requested page, request time, and browser or device information. It is used to operate the site, diagnose problems and protect it against abuse.","Successful form submissions are forwarded to my inbox through email delivery. Email providers process the message to deliver and store it. The website does not keep a separate database of enquiry messages. Hosting and email services may process information outside your country, including outside Russia and the European Economic Area.","Telegram, LinkedIn and other external links take you to separate services. They receive information when you use them and have their own privacy terms. The contact form does not automatically send your message to Telegram. The interview recording and conference photos are served by this website rather than an embedded social-media player.",[520,523],{"label":521,"href":522},"Vercel privacy notice","https:\u002F\u002Fvercel.com\u002Flegal\u002Fprivacy-notice",{"label":524,"href":525},"Telegram privacy policy","https:\u002F\u002Ftelegram.org\u002Fprivacy",{"id":527,"title":528,"paragraphs":529,"links":533},"measurement","Visitor counts and performance",[530,531,532],"On Vercel, Web Analytics measures visits and page views, and Speed Insights measures loading speed, visual stability and responsiveness. Reports help me see which content is useful and where the website needs improvement.","The measurements include page addresses, referrers, browser and device information, approximate location and performance timings. Speed Insights also receives connection information and diagnostic details about page elements. Vercel describes these reports as aggregate or anonymous; Web Analytics does not use analytics cookies.","The form fields and message are not sent as custom analytics events. I do not use advertising pixels, session recordings or automated decisions about whether to work with a client. Browser content blockers can prevent the measurement scripts from loading.",[534,537],{"label":535,"href":536},"Vercel Web Analytics: data collected","https:\u002F\u002Fvercel.com\u002Fdocs\u002Fanalytics\u002Fprivacy-policy",{"label":538,"href":539},"Vercel Speed Insights: data collected","https:\u002F\u002Fvercel.com\u002Fdocs\u002Fspeed-insights\u002Fprivacy-policy",{"id":541,"title":542,"paragraphs":543,"links":546},"language","Your language preference",[544,545],"The cookie named i18n_redirected remembers your chosen language for up to one year. On your first visit to the homepage, a supported browser language is used; otherwise the site opens in English. You can switch languages at any time.","This cookie is for language selection, not visitor tracking. You can remove it through your browser settings. The website uses locally hosted fonts; reading a page does not require a request to Google Fonts.",[],{"id":548,"title":549,"paragraphs":550,"links":554},"retention","How long I keep information",[551,552,553],"If an enquiry does not become a project, I delete the correspondence from my active inbox 12 months after our last contact. This is an inbox-cleanup policy; the website does not automatically delete email.","If we work together, project correspondence and contractual records are kept for the project and any applicable record-keeping or legal-claim requirements. Hosting logs, measurement reports and email-provider backups follow the relevant provider’s retention settings. Deleting an inbox message does not immediately remove every provider backup.","You can ask for deletion before the 12 months are up. If I need to retain particular information for a legal obligation or an active claim, I will explain what needs to be kept and why.",[],{"id":556,"title":557,"paragraphs":558,"links":561},"rights","Access, correction and deletion",[559,560],"Email contact@rand-deeb.com to ask what information I hold about you, correct it, request its deletion, or withdraw consent to processing based on your consent. If you want me to stop following up on an enquiry, say so in your message.","Depending on the law that applies, you may also have rights to restrict processing, object to it or receive your information in a portable format. I may ask for enough information to verify the request without collecting unnecessary identity documents. Withdrawing consent does not undo processing that was lawful before withdrawal.",[],{"id":563,"title":564,"paragraphs":565,"links":569},"regional-rights","Rights in your location",[566,567,568],"Russia: where Federal Law No. 152-FZ applies, you can request information about the processing of your personal data and seek correction, blocking or deletion in the circumstances provided by that law. You can raise a concern with Roskomnadzor or seek a judicial remedy.","EU and EEA: where the GDPR applies, requested project discussions rely on steps taken at your request before entering a contract; general correspondence and site security rely on the legitimate interests of responding to enquiries and operating a secure website. Processing that requires consent must have that consent. You have the applicable GDPR rights and can complain to the supervisory authority in your country. GDPR requests are normally answered within one month, with an extension where the regulation permits it.","Your location and the circumstances of the processing determine which rights and rules apply. Choosing English, Russian, Arabic or German does not change this. Visitors elsewhere can contact me about their information and any rights under their local law.",[570,573],{"label":571,"href":572},"Roskomnadzor personal-data portal","https:\u002F\u002Fpd.rkn.gov.ru\u002F",{"label":574,"href":575},"European data-protection authorities","https:\u002F\u002Fwww.edpb.europa.eu\u002Fabout-edpb\u002Fabout-edpb\u002Fmembers_en",{"id":577,"title":578,"paragraphs":579,"links":581},"changes","Changes to this notice",[580],"I update this notice when the website’s data handling changes. The date above identifies this version. Before using enquiry information for a different purpose, I will provide the information and obtain any consent required for that use.",[],{"title":583,"body":584,"label":25},"Let’s solve the next hard problem.","Tell me what you’re building, what is at stake and when you need a result. I’ll discuss the fit and propose a defined scope, deliverables and price.",1791197905517]