What I test

SaaS security, tested by someone who ships SaaS.

I focus on the modern SaaS stack — Supabase, Next.js, Stripe — where the critical holes live. Everything is manual, authorized in writing, reported in plain English. My flagship, the Zero-Leak audit: if I find no critical vulnerability, it's free.

01

The Zero-Leak Audit

The Zero-Leak Audit

SupabaseNext.jsStripe
02

Supabase & RLS Review

Row-Level Security, exposed tables, service keys — the #1 way customer data leaks.

RLSPostgresPolicies
03

API & Authorization Testing

Broken access control and IDOR — the exact class that lets me pull your customer list.

IDORBOLAAuthz
04

Auth & Multi-Tenant Isolation

Signup, login, JWT, password reset — and whether one tenant can reach another's data.

JWTSessionsTenancy
05

Payments & Webhooks

Stripe flows, price and amount tampering, and forged or replayed webhooks.

StripeWebhooks
06

Secrets & Config Exposure

Leaked API keys, env vars, and secrets accidentally shipped to the browser.

SecretsEnvClient-side
07

Free Retest

Once you've fixed the findings, I re-test them at no extra cost and confirm closure.

RetestClosure

How it works

Fixed scope, written authorization, plain-English report.

A short call to scope it, your written go-ahead, a manual test, then a report you can actually act on — plus a free retest.

Scope & authorize

We define targets and you authorize in writing. Fixed quote before anything starts.

Test & prove

Manual testing, criticals flagged the day I find them, each with real proof.

Fix & retest

Founder-readable fixes, then a free retest to confirm the door is closed.

Not sure what your SaaS needs?

Tell me your stack in two lines, I'll tell you where I'd look first. And remember: 96% of the SaaS I test have a critical vuln. If you're in the 4% where I find nothing, the Zero-Leak audit is free.