For founders, solo builders and small teams who shipped quickly with AI coding tools and now need to know whether one user can reach another user’s data.
Before launch, before taking payments or before onboarding your first business customers.
What we examine
- Review sign-up, login, sessions and password reset.
- Check who can read and change whose data, including row-level and object-level rules in Supabase, Firebase or your own API.
- Look for secrets and API keys exposed in the client, the repository or public storage.
- Test payment, webhook and admin flows that trust the client too much.
How an engagement runs
Send a short brief
The product, what changed, what you need to know and by when. A paragraph is enough, and I reply within three days.
Get a written proposal
Scope, method, exclusions, deliverables, price and dates. Confidentiality, NDA and retesting terms are agreed in the same proposal.
Follow the work as it develops
For assessments, you see evidence and priorities as they emerge. For engineering, you review the agreed milestones.
Report and walkthrough
You receive the report or the delivered work and a walkthrough with your team. Any further fixes or verification are agreed with you.
Security vulnerabilities I have reported
I have reported 150+ security vulnerabilities, including seven in Facebook and Instagram that Meta validated and acknowledged. Your application gets the same attacker’s view: authentication, permissions and the business logic between them.
See the track recordQuestions before we begin
Is this the same as an automated scan?
No. Scanners and AI review tools catch common patterns. I test the app the way an attacker would: I sign up, switch between accounts and try to reach data that is not mine.
What do you need from me?
The app URL, two test accounts with different roles and, if possible, read access to the repository and backend settings. Please do not send production passwords by email.
Which stacks do you cover?
Apps built with tools such as Cursor, Lovable, Bolt, Replit, v0 or Copilot, typically on Next.js, React, Supabase, Firebase or a Node.js API. Tell me your stack and I will confirm the fit.
How quickly will you reply?
Within three days at most. You get questions about your product or an outline of the proposal.
What does it cost?
Published prices are starting points. The final price depends on scope and technical complexity and is fixed in the written proposal before work starts.
How long does it take, and when can you start?
Duration and start date depend on the scope, the technical complexity and my current workload. The proposal states the dates.
Can we work under an NDA?
Yes. Confidentiality terms, including an NDA if you need one, are agreed as part of the proposal before you share code, credentials or findings.
Is a retest included?
Retesting is agreed for each engagement in the proposal: which findings, which version and the time window.
Do you work with agencies?
Yes. Agencies can bring me in for a client’s project. Delivery terms, including white-label reports, are agreed case by case in the proposal.
Related reading
- Axios npm compromise: how the trust chain broke
- After React2Shell: three security boundaries every server component review needs
- The 2026 Axios attack: why a clean dependency tree cannot clear a build runner