I will scan your website for exposed secrets, API keys and leaked credentials

Bangladesh

I speak Bengali, English

AI Safety Security Researcher

Security researcher and LLM systems engineer. Google VRP-credited for a disclosed authentication bypass, and acknowledged by UNICEF for a high-severity exposure affecting 13,000+ accounts. I build my...
About this Gig

Exposed API keys, forgotten .env files, leaked tokens in JavaScript bundles - these are how small teams get breached. Not sophisticated attacks. Just something left open.


I'll tell you exactly what yours is exposing.


WHAT I DO

- Scan your public web surface for exposed credentials and secrets

- Check for exposed .git, .env, backup and config files

- Review JavaScript bundles for hardcoded keys and tokens

- Verify every finding manually before reporting it


WHAT YOU GET

A clear report with each finding rated by real business impact - what an attacker could actually do with it - plus exact steps to fix. Not a raw scanner dump.


WHY ME

Google VRP credited for a responsibly disclosed authentication bypass. Acknowledged by UNICEF for a high-severity exposure affecting 13,000+ accounts. I built the scanning engine I use.


IMPORTANT - AUTHORIZATION

I only test systems you own or are authorized to test. Please confirm this when ordering. Passive-first: I look, I never break. Nothing is modified, exploited or taken offline.


Message me before ordering if you're unsure about scope - I'll tell you honestly whether I can help.

Testing application:

Web application

Development technology:

JavaScript

Node.js

PHP

Python

Device:

PC

Mac

Linux

My Portfolio