For security product teams and engineering organizations building analysis capabilities, extending scanners or evaluating the quality of their security testing tools.
When you need to build, extend or evaluate a security analysis capability.
What we examine
- Define the analysis goal, target technologies, access, constraints and acceptance criteria.
- Design the agreed architecture or implement and extend selected analysis, detection or scanning components.
- Evaluate the agreed capabilities against representative targets, documenting coverage, findings and limitations.
- Plan integration and handoff around the team’s workflow and maintenance needs.
A clear start. A useful finish.
Tell me the problem
Share the product, stack, goal and deadline. A short overview is enough to start the conversation.
Agree the engagement
Receive a written scope, deliverables, acceptance criteria, price and schedule before we begin.
Review the work as it develops
For assessments, examine the evidence and priorities. For engineering, review agreed implementation milestones.
Put the result to work
Get a technical walkthrough and useful handoff. Agree any further implementation or verification your team needs.
I can build the system behind the solution.
My work spans software architecture, implementation and security research. I designed and developed Hendra’s context-aware scanning architecture. That experience is useful when your challenge needs engineering as well as investigation.
See how I built HendraQuestions before we begin
Do you develop security tools?
Yes. I design and develop SAST and DAST applications. An engagement can cover architecture, selected detection components, extensions, integration or evaluation. The proposal defines the target technologies and what will be delivered.
What have you built?
Hendra is my modular, context-aware DAST scanner developed during completed doctoral research at ITMO University. I designed its core architecture, technology identification, scan planning, request deduplication, finding review and benchmarking approach.
Can you extend an existing tool?
Yes, where its architecture, access and licensing permit the agreed work. We first establish the extension points, required behavior and tests for the target capability.
Which languages can a SAST project cover?
Language coverage is defined for each project. We review the target language, available analysis infrastructure, code patterns and evaluation cases before agreeing development. Coverage and limitations are documented.
Can you evaluate a tool before we invest in development?
Yes. A scoped evaluation can examine detection behavior, useful coverage, triage effort and integration constraints. Published lab benchmarks provide context; the evaluation needs targets and criteria relevant to your team.
Useful lessons from security research
- After React2Shell: three security boundaries every server component review needs
- The 2026 Axios attack: why a clean dependency tree cannot clear a build runner
- CVE-2024-26855: when a missing attribute becomes a NULL dereference