Scope & authorize
We define targets and you authorize in writing. Fixed quote before anything starts.
What I test
I focus on the modern SaaS stack — Supabase, Next.js, Stripe — where the critical holes live. Everything is manual, authorized in writing, reported in plain English. My flagship, the Zero-Leak audit: if I find no critical vulnerability, it's free.
The Zero-Leak Audit
Row-Level Security, exposed tables, service keys — the #1 way customer data leaks.
Broken access control and IDOR — the exact class that lets me pull your customer list.
Signup, login, JWT, password reset — and whether one tenant can reach another's data.
Stripe flows, price and amount tampering, and forged or replayed webhooks.
Leaked API keys, env vars, and secrets accidentally shipped to the browser.
Once you've fixed the findings, I re-test them at no extra cost and confirm closure.
How it works
A short call to scope it, your written go-ahead, a manual test, then a report you can actually act on — plus a free retest.
We define targets and you authorize in writing. Fixed quote before anything starts.
Manual testing, criticals flagged the day I find them, each with real proof.
Founder-readable fixes, then a free retest to confirm the door is closed.
Tell me your stack in two lines, I'll tell you where I'd look first. And remember: 96% of the SaaS I test have a critical vuln. If you're in the 4% where I find nothing, the Zero-Leak audit is free.