For owners and developers of web products, SaaS platforms and APIs preparing a release, changing a sensitive feature or responding to a customer security request.
Before shipping a sensitive web feature or opening an API to customers.
What we examine
- Agree the application, API endpoints, environments, accounts and testing boundaries.
- Review authentication, authorization, input handling and relevant business logic.
- Validate attack paths and their impact within the agreed scope.
A clear start. A useful finish.
Tell me the problem
Share the product, stack, goal and deadline. A short overview is enough to start the conversation.
Agree the engagement
Receive a written scope, deliverables, acceptance criteria, price and schedule before we begin.
Review the work as it develops
For assessments, examine the evidence and priorities. For engineering, review agreed implementation milestones.
Put the result to work
Get a technical walkthrough and useful handoff. Agree any further implementation or verification your team needs.
I can build the system behind the solution.
My work spans software architecture, implementation and security research. I designed and developed Hendra’s context-aware scanning architecture. That experience is useful when your challenge needs engineering as well as investigation.
See how I built HendraQuestions before we begin
Can the assessment include APIs?
Yes. Specify the API, available documentation, account roles and related application workflows. We agree the endpoints and relevant integrations in scope.
Can you assess a production application?
The environment, permitted actions and operational limits are agreed first. Share availability requirements and other constraints when discussing scope.
Can you check business logic and permissions?
Yes, where the agreed access and scope support it. Product rules, account roles and sensitive workflows help define useful tests.
How are timing and price determined?
By the targets, access, complexity, testing depth and deliverables. The written proposal defines scope and terms before testing begins.
Useful lessons from security research
- After React2Shell: three security boundaries every server component review needs
- The 2026 Axios attack: why a clean dependency tree cannot clear a build runner
- CVE-2024-26855: when a missing attribute becomes a NULL dereference