Independent offensive security · Maasmechelen, Belgium
I break web apps, APIs and mobile apps before somebody else does it for free.
Manual, business-logic-first penetration testing by a named researcher — not a scanner report with a consultancy logo on the front. Fourteen accepted findings at OpenAI, a place in Google’s hall of fame, and a report your developers can actually act on — scoped, tested and delivered inside one week.
Findings accepted at OpenAI
Fourteen separate vulnerabilities reported to and accepted by OpenAI.
Honourable mentions
Listed in Google's Vulnerability Reward Program honourable mentions.
Intigriti, within one month
Reached the platform top 20 in a single month of hunting, then moved to client work.
Teaching offensive security
One of the most-followed independent voices in application security.
What I test
Three surfaces, tested by hand.
Every engagement is fixed-price, fixed-date, and finished inside one week. You know the cost and the calendar before anything starts.
Web application
Authenticated, multi-role testing of the whole application — not a scanner report with a logo on it. Broken access control and business-logic abuse are where I spend most of the engagement, because that is where the findings that matter actually live.
- Broken access control (IDOR, horizontal & vertical privilege escalation)
- Business-logic and workflow abuse
- Injection: XSS, SQLi, SSTI, XXE, command injection
- Authentication, session handling and password-reset flows
- SSRF, file upload and deserialisation
- Tenant isolation in multi-tenant SaaS
From
€4,000
API
REST, GraphQL and gRPC, tested against the spec and then well beyond it. APIs fail on authorisation far more often than on injection, so every endpoint is exercised across every role — including the ones your documentation does not mention.
- Object- and function-level authorisation (BOLA / BFLA)
- Mass assignment and excessive data exposure
- GraphQL introspection, batching and query-depth abuse
- Rate limiting, resource consumption and enumeration
- JWT, OAuth 2.0 and API-key handling
- Undocumented, deprecated and shadow endpoints
From
€3,000
Mobile application
iOS and Android, tested on real devices. Static review of the binary, dynamic instrumentation at runtime, and full testing of the backend the app talks to — because a mobile app is mostly an API client wearing a nice interface. A single platform takes less; both fit inside the week.
- Insecure local storage, keychain and keystore misuse
- Certificate pinning bypass and traffic interception
- Runtime instrumentation with Frida and Objection
- Hardcoded secrets and reverse engineering of the binary
- Deep links, IPC and exported component abuse
- The backing API, tested to the same depth as a standalone API engagement
From
€5,000
How it runs
Five steps, no surprises.
The same process every time, whether it is a three-day API review or a full mobile engagement — structured on PTES, tested to OWASP's guides.
Methodology
Engagements are structured on the Penetration Testing Execution Standard (PTES), and the testing itself follows OWASP's Web Security Testing Guide and Mobile Application Security Testing Guide. That means the coverage is a published checklist rather than one tester's habits — you can read the standard and see exactly what was in scope.
- PTES
- Penetration Testing Execution StandardEngagement structure, end to end
- OWASP WSTG
- Web Security Testing GuideWeb application and API testing
- OWASP MASTG
- Mobile Application Security Testing GuideiOS and Android testing
Scope & rules of engagement
A 45-minute call to agree targets, roles, test accounts, out-of-scope systems and a testing window. You get a fixed price and a fixed date before anything starts — no hourly surprises. A 30% deposit on signature holds the dates.
Recon & mapping
Full attack-surface mapping: every endpoint, parameter, role and state transition. This is the phase most vendors rush, and it is the reason their reports read like a scanner's.
Manual exploitation
The bulk of the engagement. Automated tooling runs in the background for coverage, but every reported finding is manually verified and manually exploited. No unvalidated scanner output ever reaches your report.
Reporting
Each finding gets reproduction steps a developer can follow, a CVSS 4.0 score, real business impact in plain language, and a concrete fix. Plus a one-page executive summary that a non-technical board can read.
Debrief & free retest
A live walkthrough with your engineers to answer questions while the context is fresh. Once you have shipped fixes, I retest every finding free of charge within 90 days and issue an updated attestation letter.
Pricing
Published rates, fixed quotes.
Most security vendors hide their pricing so they can work out what you can afford. Here is mine.
Essential
One target, tested properly. Right for a startup heading into its first security review, or a single new feature that needs eyes on it before launch.
- One web app, one API or one mobile platform
- Grey-box, single authenticated role
- Full findings report with reproduction steps
- Executive summary
- Free retest within 90 days
Professional
The engagement most clients actually need: the application and the API behind it, tested across every role, with the authorisation matrix fully exercised.
- Web app plus its backing API, or a full mobile platform
- Multi-role, authenticated, full authorisation matrix
- Business-logic and tenant-isolation testing
- Findings report, executive summary, CVSS 4.0 scoring
- Letter of attestation for your customers and auditors
- Live remediation call with your engineers
- Free retest within 90 days
Continuous
For teams shipping every week. A standing engagement where each release gets looked at, rather than one annual audit that is stale by March.
- Five testing days every month — a full engagement week, rolled over up to 3 months
- Unlimited retests, no 90-day window
- Priority scheduling — 5 working days' notice
- Direct Slack or Teams channel for your engineers
- Quarterly attestation letters
- Annual full-depth engagement at a 15% discount
- All engagements are fixed-price, quoted from a €1,000/day rate. You approve the scope and the number of days before any work starts.
- No engagement runs longer than one week. If a target genuinely needs more than five days, it is two scoped engagements with a report after each — never an open-ended bill.
- A 30% non-refundable deposit is payable on signature; it secures your testing window in the calendar. The balance falls due on delivery of the report, net 14 days.
- Prices exclude 21% Belgian VAT. VAT is not charged on reverse-charge invoices to VAT-registered businesses outside Belgium.
- Retesting beyond the included window, out-of-hours testing and on-site work are quoted separately.
Track record
Public, verifiable, and not a stock photo.
One client below is named with their permission; the rest of the client work stays under NDA. Everything else here is disclosed under the bug-bounty programmes' own rules, so every line is checkable.
Selected client
Poloniex
Cryptocurrency exchange
Named with permission. What was tested and what was found stay under NDA, as with every client.
OpenAI
14 findingsMy own finding
Fourteen separate vulnerabilities reported to and accepted by OpenAI, including broken access control in a Tier 1 product that was reopened and escalated to P3 after new technical evidence.
My own finding
Listed in Google's Vulnerability Reward Program honourable mentions, with a report accepted into the programme and assigned to an internal engineer for fixing.
Intigriti
Top 20My own finding
Reached the platform's top 20 within a single month of hunting — 562 reputation across 39 accepted submissions — then moved on to client engagements.
Greenhost
€2,000Found by a hunter I coached
A hunter I coached landed the highest payout the programme had ever awarded, for a serious PII leak. The company published a blog post about the fix.
I wrote the certifications other people study for
Three professional certifications — web, API and network penetration testing — built from years of doing the work rather than from a syllabus. Alongside them, the hunters I coach have landed first triages at Google, P3s at OpenAI, and the largest payout a programme had ever made. Codifying a method well enough that other people can pass an exam on it, and then land real bugs with it, is a harder test of that method than only using it yourself. Your engagement gets the same method, from the person who wrote it.
Authored
Website penetration testing
Authored
API penetration testing
Authored
Network penetration testing
Questions
Before you ask
Forty-five minutes, no charge and no slide deck. You describe the application, who uses it and what would hurt most if it leaked; I ask enough questions to size the work honestly. You leave with a scope, a fixed price and a date. If penetration testing is not what you actually need yet, I will tell you that instead of selling you one.
Next step
Tell me what you have built.
A 45-minute call, no charge and no pitch deck. You describe the application, I tell you what testing it properly costs and how long it takes. If it is not worth doing, I will say so.
Phone
+32 456 93 11 20Based in
Maasmechelen, Belgium
Remote across the EU · on-site on request
Pick a slot directly in my calendar — no back-and-forth
