Finding the vulnerabilities
others miss.

Independent bug bounty hunter and security consultant based in the United Kingdom. I help organisations ship safer products through hands-on offensive testing and responsible disclosure.

// 01

Services

Engagements scoped to your needs — from a single app review to ongoing private bug bounty support.

Web Application Testing

Deep, manual testing of web apps and APIs — auth flows, access control, injection, business-logic and chained exploits that scanners never catch.

API & Cloud Security

REST/GraphQL API review, IDOR & broken-object-level-auth hunting, plus cloud misconfiguration assessment across AWS, GCP and Azure.

Mobile App Testing

Android & iOS assessments — static and dynamic analysis, insecure storage, certificate pinning bypass and API backend testing.

Bug Bounty Triage

Run a programme? I help triage incoming reports, validate severity and reduce noise so your team focuses on what actually matters.

Vulnerability Research

Targeted research against your product or a specific technology, with clear, reproducible reports and responsible disclosure handling.

Security Consulting

Threat modelling, secure-design reviews and remediation guidance — practical advice your engineers can actually act on.

// 02

Skills & Toolkit

A working knowledge of the offensive security stack — and the methodology to use it well.

Disciplines

  • OWASP Top 10
  • Access Control / IDOR
  • Authentication & Sessions
  • SSRF
  • XSS / CSRF
  • SQL / NoSQL Injection
  • Business Logic
  • Race Conditions
  • Deserialization

Tooling

  • Burp Suite Pro
  • nmap
  • ffuf
  • sqlmap
  • Nuclei
  • Frida
  • Wireshark
  • Metasploit
  • Custom Python tooling

Platforms

  • HackerOne
  • Bugcrowd
  • Intigriti
  • YesWeHack
  • Private programmes

// 03

Hire me

Got a target that needs testing, or a programme that needs a sharp set of eyes? Let's talk.

I take on a limited number of engagements at a time to keep quality high. The fastest way to reach me is email — encrypted contact welcome (PGP key below).

pgp 0xDEADBEEF DEADBEEF DEADBEEF

Prefer email? you@example.com