Service line · Secure
Security and compliance engineering
Find the holes before someone else does, and make the code do what the policy promises.
I audit and harden web applications and infrastructure: authentication, access control, injection, configuration and secrets, with a fix list your team can act on. I completed the Google Cybersecurity Specialization. I do engineering, not legal advice, and I work alongside your counsel.
Sound familiar?
- Your app was built fast, maybe with AI tools, and you're not sure what it exposes.
- An enterprise customer sent a security questionnaire you can't answer yet.
- You're about to launch and want to know what an attacker would see first.
Questions
Is this legal advice?
No. I implement and test the technical measures that laws and standards call for, and document them. Deciding which obligations apply to your business is for your lawyer; I work alongside them.
Can you sign an NDA before seeing our code?
Yes, before we discuss any detail. Findings are shared only with the people you name.
Tell me what you’re building.
Tell me about the problem. I’ll reply with the smallest useful first step and when I could start.