ABOUT solo · independent · application security

Narrow practice.
Deep operator advantage.

I review the trust boundaries in founder-led, AI-coded SaaS—the auth, tenancy, integrations, business logic, and agent surfaces most likely to inherit repeatable mistakes.

The thesis

LLMs repeat architecture mistakes.

Models sample from a shared training distribution. They reproduce the same plausible-looking OAuth callbacks, middleware gaps, RLS policies, URL fetchers, and token checks across unrelated products.

That makes the bugs fingerprintable. The advantage is not generic “cybersecurity”; it is knowing where AI-scaffolded applications tend to put trust in the wrong tier, then testing those boundaries by hand.

Operating model

Two tracks, never one blurred funnel.

01COMMERCIAL

Paid, authorized reviews

Qualify the business need, agree scope, authorization, and payment before testing, then deliver evidence, remediation support, and a re-test.

See the engagement model →
02PUBLIC INTEREST

Independent research

Researcher-owned accounts, minimum reproducible proof, private disclosure, remediation first, and publication on a responsible timeline.

Read the advisories →

The operator

Edu

Independent application-security researcher

I work directly with the founder or technical owner. There is no account team between the scope conversation, the testing, the report, and the re-test.

Practice
Solo and hand-driven
Capacity
Two reviews per month
Public record
2 CVEs · 3 GHSAs
Client work
Private unless approved

Non-negotiables

How the work stays useful and safe.

01

Written authority

No hands-on client testing before the system boundary and permission are explicit.

02

Stop at proof

Prove impact with the smallest safe action. No persistence, dumping, or destructive theater.

03

Fixable evidence

Every finding includes reproduction, impact, root cause, and a concrete remediation path.

04

No paywall on disclosure

An independently discovered vulnerability is disclosed for remediation whether or not paid work follows.

Work together

Start with what changed.

Send the product, business deadline, and high-risk workflow. I will tell you whether there is a sensible fixed scope.

Scope a security review