For product owners, CTOs and development teams preparing a release, responding to a customer assessment request or checking an existing product.
Before a release, customer review or important product change.
What we examine
- Define the product, versions, environments, access and permitted testing.
- Investigate relevant attack paths, trust boundaries and security-sensitive functionality.
- Validate findings and explain their impact within the agreed scope.
A clear start. A useful finish.
Tell me the problem
Share the product, stack, goal and deadline. A short overview is enough to start the conversation.
Agree the engagement
Receive a written scope, deliverables, acceptance criteria, price and schedule before we begin.
Review the work as it develops
For assessments, examine the evidence and priorities. For engineering, review agreed implementation milestones.
Put the result to work
Get a technical walkthrough and useful handoff. Agree any further implementation or verification your team needs.
I can build the system behind the solution.
My work spans software architecture, implementation and security research. I designed and developed Hendra’s context-aware scanning architecture. That experience is useful when your challenge needs engineering as well as investigation.
See how I built HendraQuestions before we begin
Can you test web, mobile and desktop applications?
Yes. Share the product, platform and goal. We will define the targets, methods and access appropriate to your application. Web and API security are my strongest and preferred area of practice.
What if we only need one feature checked?
We can scope a focused review of a critical workflow or component. The proposal makes its boundaries clear so you know what has and has not been assessed.
How do you determine price and timing?
From the targets, complexity, access, depth and required deliverables. You receive an agreed scope, price and schedule before testing begins.
Is fix verification included?
We agree any retesting allowance in the proposal, including the findings, version and time window. Further remediation or verification can also be a separate engagement.
Useful lessons from security research
- Security code review or penetration testing: what should you buy?
- After React2Shell: three security boundaries every server component review needs
- The 2026 Axios attack: why a clean dependency tree cannot clear a build runner