Web Application Testing
Deep, manual testing of web apps and APIs — auth flows, access control, injection, business-logic and chained exploits that scanners never catch.
root@uk:~$ whoami
root@uk:~$ cat about.txt
UK-based bug bounty hunter & offensive security researcher.
I find the bugs before the bad actors do.
root@uk:~$ █
Independent bug bounty hunter and security consultant based in the United Kingdom. I help organisations ship safer products through hands-on offensive testing and responsible disclosure.
// 01
Engagements scoped to your needs — from a single app review to ongoing private bug bounty support.
Deep, manual testing of web apps and APIs — auth flows, access control, injection, business-logic and chained exploits that scanners never catch.
REST/GraphQL API review, IDOR & broken-object-level-auth hunting, plus cloud misconfiguration assessment across AWS, GCP and Azure.
Android & iOS assessments — static and dynamic analysis, insecure storage, certificate pinning bypass and API backend testing.
Run a programme? I help triage incoming reports, validate severity and reduce noise so your team focuses on what actually matters.
Targeted research against your product or a specific technology, with clear, reproducible reports and responsible disclosure handling.
Threat modelling, secure-design reviews and remediation guidance — practical advice your engineers can actually act on.
// 02
A working knowledge of the offensive security stack — and the methodology to use it well.
// 03
Got a target that needs testing, or a programme that needs a sharp set of eyes? Let's talk.
I take on a limited number of engagements at a time to keep quality high. The fastest way to reach me is email — encrypted contact welcome (PGP key below).
pgp 0xDEADBEEF DEADBEEF DEADBEEF