I'm an independent security researcher hunting on HackerOne, focused on web application and API security. I look for real, exploitable vulnerabilities and report them responsibly — no noise, no guesswork, just verified findings.
Security research grounded in manual verification — not scanner output dressed up as a finding.
Hunting for vulnerabilities through HackerOne-hosted programs, within each program's defined scope and rules.
Authentication, session handling, access control, injection points, and business-logic edge cases.
Auth bypass, IDOR, schema abuse, and misconfiguration testing across REST and GraphQL APIs.
Clear, reproducible reports with verified impact — written to help teams fix issues fast, not to pad a count.
Every finding goes through the same discipline before it's ever written up.
Map the target and confirm what's in scope.
Manual + tool-assisted probing of attack surface.
Confirm real, reproducible impact — reject false positives.
Clear write-up with PoC, steps, and severity.
Support retesting once a fix ships.
My process is deliberate: understand the target, test methodically, and verify real, reproducible impact before ever calling something a vulnerability. Every report I submit is written the way I'd want to receive one — clear, evidenced, and easy for a triager to act on fast.
I'd rather submit fewer, high-quality reports than chase volume with scanner output. That discipline is the standard I hold every finding to.
For vulnerability disclosures or general inquiries, reach out below.