Authorized application security · founder-led SaaS

Security review for the moment your SaaS has to stand up to scrutiny.

Preparing for due diligence, an enterprise customer, or a sensitive launch? I test the auth, tenancy, integrations, and business logic most likely to fail under real attack.

Written scope and authorization before testing. Staging preferred. No customer-data access.

2paid engagements delivered
2 CVEspublic vulnerability records
3 GHSAsGitHub Security Advisories
1verification re-test included
LIMITED LAUNCH OFFER 3 slots · $495 prepaid · 48 hours

Outbid and high-traffic launches

Before the traffic tests it for you.

Pick the one product surface you would least want unfamiliar users pressure-testing. I will review that boundary with written authorization and deliver evidence your engineer can act on.

Scope
One critical surface
Turnaround
48 hours
Included
Evidence, fixes, one re-test
Price
$495 prepaid
Claim a triage slot

Expand within 7 days and the $495 is credited toward the full $1,500 Focused Security Sprint. Staging preferred.

Why now

Security becomes urgent when the business changes.

Vulnerability risk is always present. Buying intent appears when a deadline makes that risk commercially expensive.

01

Due diligence starts

A buyer, investor, or broker needs a credible view of technical risk before the transaction moves.

02

An enterprise asks

Procurement sends a questionnaire and needs evidence behind the answers, not another policy document.

03

The attack surface changes

You are shipping teams, OAuth connectors, payments, agents, a public API, or a desktop client.

What gets tested

The trust boundaries most likely to fail.

The scope follows the product and the business event—not a generic scanner checklist.

01

Identity

Authentication, recovery, invitations, roles, and session boundaries.

02

Tenancy

Cross-tenant reads and writes, RLS drift, ownership, and admin paths.

03

Integrations

OAuth state, callbacks, webhooks, connector tokens, and org binding.

04

Business logic

Billing state, quotas, race conditions, and workflow authorization.

05

Agent surfaces

URL fetching, SSRF, prompt boundaries, tools, and code execution.

06

Client software

Desktop/mobile credentials, local services, updates, and binary trust.

Fixed-scope offers

Choose the review that matches the moment.

Every engagement includes written scope, reproducible evidence, remediation guidance, and a verification re-test.

Focused security sprint

$1,500

One high-risk surface, such as tenant isolation, OAuth, billing, or URL fetching.

See scope →

Deep assessment

from $6,000

Desktop/mobile clients, multiple connectors, agent execution, or broad multi-surface products.

See scope →

Safe by construction

Serious testing without making production your laboratory.

The assessment boundary is explicit before work begins. Testing uses staging and client-provided or researcher-owned accounts wherever possible, stops at proof, and excludes destructive behavior.

Read the methodology →
  • 01Written scope and authorization
  • 02Staging preferred; production only by agreement
  • 03No real customer-data access
  • 04No persistence, exfiltration, or denial of service
  • 05Stop at minimum reproducible proof
  • 06Patch support and verification included

Independent research

Public work, responsibly disclosed.

Research produces fixes, advisories, and public knowledge. It is not client work performed before a commercial agreement.

  1. parakeetai CRITHIGH
    Four flaws in an AI interview assistant's web/API stack →
  2. cossistant CRIT
    A support-chat widget where knowing someone's email is enough to read their private conversations — on every site that installs it →
  3. kelviq MED
    A Merchant-of-Record API that hands back its own webhook secrets, enumerates its whole seller base, and ships its internal schema on a public host →

All research and advisories → 2 CVEs · 3 GHSAs · coordinated disclosure first

Start with the business event

What changed—and when does it matter?

Send the product URL, the customer or transaction deadline, and the surface you are most concerned about. I will tell you whether there is a sensible fixed scope.

Scope a security review