For product and engineering teams acting on an assessment, vulnerability report or important security change.
When you have findings and need a clear path to closing them.
What we examine
- Review the original evidence, affected version and proposed changes.
- Discuss root causes, remediation options and priorities with the responsible team.
- Verify agreed fixes against the original issue and relevant related behavior.
A clear start. A useful finish.
Tell me the problem
Share the product, stack, goal and deadline. A short overview is enough to start the conversation.
Agree the engagement
Receive a written scope, deliverables, acceptance criteria, price and schedule before we begin.
Review the work as it develops
For assessments, examine the evidence and priorities. For engineering, review agreed implementation milestones.
Put the result to work
Get a technical walkthrough and useful handoff. Agree any further implementation or verification your team needs.
I can build the system behind the solution.
My work spans software architecture, implementation and security research. I designed and developed Hendra’s context-aware scanning architecture. That experience is useful when your challenge needs engineering as well as investigation.
See how I built HendraQuestions before we begin
Can you work with a report from another assessor?
Yes, subject to access and sufficient evidence. We first establish what the original findings show and what needs reproduction, clarification or verification.
Will you implement the fixes?
Developer consultation and verification can be scoped independently. Any implementation or patch work requires its own agreed responsibility, access and acceptance criteria.
Does a successful retest mean the whole product is secure?
It establishes the result of the agreed checks on the tested version. The verification report identifies its scope and does not substitute for an assessment of unrelated areas.
Useful lessons from security research
- The 2026 Axios attack: why a clean dependency tree cannot clear a build runner
- After React2Shell: three security boundaries every server component review needs
- CVE-2024-26855: when a missing attribute becomes a NULL dereference