About

I'm not a security consultant. I'm a founder who codes like you.

I've been building SaaS for 4 years — several launched, automations for infopreneurs, on the same stack as most of my clients: Supabase, Next.js, Stripe. I don't parachute in from the outside; I code in the same trench. For the past 2 years I've pentested SaaS, only with written authorization.

170+
SaaS audited
96%
had a critical vuln
30 min
to pull your customer data
200k$
dev budget, breached anyway

Why me

I know your bugs because I've shipped them myself.

I'm not a generalist pentester with a diploma. I'm a founder who pentests other founders. I've audited 170+ SaaS — small products and ones built by real teams alike, dev budgets from $20k to $200k. The budget tells you nothing about exposure: 96% had a critical vulnerability, because the modern stack generates the holes mechanically, no matter how serious the team.

The dangerous belief

“I paid a real dev team, so I'm covered.”

That's exactly the most dangerous belief there is. Across 170+ SaaS I've audited, 96% had a critical vulnerability — including products built for up to $200k. Your dev budget says nothing about your exposure: the stack generates the holes regardless of how good the team is. A clean, fast, beautiful app can have its database wide open.

How I work

Six things I hold to on every engagement.

01

Same trench

I build on Supabase, Next.js and Stripe too. I test the exact stack you ship on — not a textbook version of it.

02

Works ≠ protected

Your tools ship an app that works, not one that's protected. Nobody warns you about the difference. I do.

03

Written authorization only

I only test what you own and explicitly authorize, in writing. No exceptions, ever.

04

Founder-readable reports

No 80-page PDF of scanner noise. Clear findings, real proof, and fixes you can ship this week.

05

Real proof, not theory

Every critical comes with a working proof — like pulling your own customer list — so there's no debate about severity.

06

Your data stays yours

Scoped access, careful handling, and everything deleted when the engagement ends.

Want to see what's actually exposed?

Give me your scope and written go-ahead. I'll show you what an attacker reaches first — and if I find no critical vulnerability, the Zero-Leak audit is free.