Due diligence starts
A buyer, investor, or broker needs a credible view of technical risk before the transaction moves.
Authorized application security · founder-led SaaS
Preparing for due diligence, an enterprise customer, or a sensitive launch? I test the auth, tenancy, integrations, and business logic most likely to fail under real attack.
Written scope and authorization before testing. Staging preferred. No customer-data access.
Outbid and high-traffic launches
Pick the one product surface you would least want unfamiliar users pressure-testing. I will review that boundary with written authorization and deliver evidence your engineer can act on.
Expand within 7 days and the $495 is credited toward the full $1,500 Focused Security Sprint. Staging preferred.
Why now
Vulnerability risk is always present. Buying intent appears when a deadline makes that risk commercially expensive.
A buyer, investor, or broker needs a credible view of technical risk before the transaction moves.
Procurement sends a questionnaire and needs evidence behind the answers, not another policy document.
You are shipping teams, OAuth connectors, payments, agents, a public API, or a desktop client.
Paid & authorized work
Client work appears only with approval. Independent research is tracked separately below.
An authorized review of a credential-bearing desktop and meeting workflow.
● Delivered · client-approved listing
A focused review of customer-data, account, and OAuth surfaces.
● Delivered · confidential
What gets tested
The scope follows the product and the business event—not a generic scanner checklist.
Authentication, recovery, invitations, roles, and session boundaries.
Cross-tenant reads and writes, RLS drift, ownership, and admin paths.
OAuth state, callbacks, webhooks, connector tokens, and org binding.
Billing state, quotas, race conditions, and workflow authorization.
URL fetching, SSRF, prompt boundaries, tools, and code execution.
Desktop/mobile credentials, local services, updates, and binary trust.
Fixed-scope offers
Every engagement includes written scope, reproducible evidence, remediation guidance, and a verification re-test.
Focused security sprint
$1,500
One high-risk surface, such as tenant isolation, OAuth, billing, or URL fetching.
See scope →Due-diligence readiness
$2,500–$3,500
Auth, tenancy, integrations, sensitive data flow, and a buyer-facing remediation summary.
See scope →Deep assessment
from $6,000
Desktop/mobile clients, multiple connectors, agent execution, or broad multi-surface products.
See scope →Safe by construction
The assessment boundary is explicit before work begins. Testing uses staging and client-provided or researcher-owned accounts wherever possible, stops at proof, and excludes destructive behavior.
Read the methodology →Independent research
Research produces fixes, advisories, and public knowledge. It is not client work performed before a commercial agreement.
All research and advisories → 2 CVEs · 3 GHSAs · coordinated disclosure first
Start with the business event
Send the product URL, the customer or transaction deadline, and the surface you are most concerned about. I will tell you whether there is a sensible fixed scope.
Scope a security review