API security
Reviewing authentication, authorization, object access, input handling, and business logic across the interfaces that connect modern products.
Independent research across API, web, and mobile attack surfaces, supported by responsible disclosure and security-conscious software engineering.
Security work is handled with clear scope, careful evidence, and disclosure practices designed to help owners remediate safely.
Reviewing authentication, authorization, object access, input handling, and business logic across the interfaces that connect modern products.
Examining browser, server, and mobile attack surfaces with testing scoped to avoid harm and protect user information.
Reporting reproducible findings privately, allowing time for remediation, and publishing only material that is safe to share.
Explore this topic