I will map your external attack surface and find what you forgot you exposed
Manual pentesting for web apps, APIs and AI generated code
About this Gig
Guarantee: every finding comes with the exact request that reproduces it. If you cannot reproduce one on your own system, I remove it and refund that part.
Most breaches start somewhere nobody meant to publish. A forgotten staging host. An old subdomain still pointing at a dead service. A storage bucket left open. A key committed to a public repository.
I look at your company the way an attacker does before touching anything: from the outside, without credentials, without sending anything intrusive.
What you get: every asset I can attribute to you, what is exposed on it, which findings are actually reachable, and what to shut down first.
Passive by default. Nothing intrusive is sent, and nothing is tested actively without your written authorisation.
Nineteen years on Linux and networks before moving into security research: DNS and mail, VPNs, dual-stack IPv4 and IPv6, AWS networking and IAM.
Everything runs in writing. No calls needed.
Testing application:
Website
Development technology:
HTML & CSS
•
JavaScript
•
Node.js
•
PHP
•
Python
Device:
PC
•
Mac
•
Linux
•
iPhone
•
Android mobile phone
My Portfolio
FAQ
Is this intrusive? Will it set off alarms?
No. The default is passive: public sources and observation only. Anything active happens only after you authorise it in writing.
What if you find nothing exposed?
You get the full inventory anyway, and a written statement of what was checked. That is the document an auditor or a customer security questionnaire asks for.
Do we need a call?
No. I work entirely in writing and deliver the review as a document.

