Vulnerabilities found before hackers do.
Your vulnerabilities already exist. The only question is who finds them first.
Who better than an ethical hacker to find your vulnerabilities?
An attacker only needs one flaw. My job is to find it before they do. I think like them: patient, methodical, quiet. Where automated tools stop, I keep going, uncovering the weaknesses in your system until I reach the one that truly threatens your business. Then, instead of walking away with what I found, I hand you everything you need to fix the vulnerabilities for good.
Adversarial mindset
Real attacker logic. I hunt the path no scanner will ever find.
Real-world rigor
Hands-on experience built on high-traffic platforms and sensitive environments.
Absolute discretion
Strict confidentiality, NDA as standard, encrypted reports if needed.
An audit shaped around your situation.
Whether you're launching a site or looking to secure a service already live, these are the engagements I run most often.
Pre-launch audit
Catch flaws while they still cost a fix, not an incident, before your site or feature ever goes live.
Live production testing
Already online? I test it the way a real attacker would, quietly, and without breaking anything.
API audit
REST, JSON, GraphQL: I make sure every endpoint exposes only what it should, and only to whoever should reach it.
Auth & access review
Who can reach what? I hunt the access that crosses the lines you set: IDOR, privilege escalation, broken permissions.
Continuous testing
Coverage over time instead of a one-off snapshot: I keep testing as your perimeter evolves.
Second opinion & post-incident
A doubt after an alert or a major change? I confirm what's real, qualify the impact, and document it.
Anything that takes a request, I'll test.
From a brochure site to a complex business platform: any surface reachable from a browser or an API is a potential target, and therefore a candidate for penetration testing.
The vulnerabilities I go after.
In practice, here are the doors an attacker tries to open. The gist fits in one line for newcomers; the technical detail is there for experts.
Injections & input
Making the app run what it shouldn't.
Access & identity
Seeing or doing what isn't yours.
API & logic
Bending business rules and authorizations.
Server & config
Exploiting a setting left open.
A repeatable path from recon to retest.
Recon & mapping
I map everything you have exposed, including the subdomains, endpoints and forgotten flows you didn't know were still online.
Surface analysis
I learn your roles, trust boundaries and business logic before attacking, to aim precisely rather than broadly.
Manual exploitation
Where scanners are blind, I hand-craft attacks and chain weaknesses into real, demonstrable impact.
Impact & proof
A reproducible proof of concept: you see exactly what an attacker could reach.
Clear reporting
Priorities both leadership and engineers can read, with what to fix and in what order.
Retest & close
I re-check every fix myself: a flaw is only closed once I've confirmed it.
What you receive after my engagement.
Work your teams, or your providers, can act on immediately, with every finding proven and explained.
Prioritized report
Every flaw ranked by real severity and urgency, so the most dangerous gets fixed first, not the loudest.
Reproducible proof of concept
The exact steps to replay each flaw. No "maybe", no theory, proof you can hand straight to your developers.
Business impact
In plain language: what it exposes, what it could cost, and who is affected. Readable without a security background.
Concrete remediation
Not just "it's broken": how to fix it, step by step, in a way your team can actually apply.
Retest included
Once you've patched, I re-check your fixes. The door is shut, and verified, not assumed.
Debrief & handover
A walkthrough of the report with your team, so the findings are understood and owned, not just delivered.
Focused where it counts: web and APIs.
I focus on two surfaces: the web and the APIs, exactly where your customer data, your payments and your access controls live. Depth over breadth: I'd rather know these environments inside out than scan everything at the surface, where the costly vulnerabilities never show.
The web layer
Websites, web apps, customer portals, client areas, back-offices and CMS: the full interface your users and staff touch.
The API layer
REST and JSON APIs, authentication, authorization, and the third-party integrations that hold everything together.
Native mobile is outside my scope. For that, I'll happily point you to a trusted specialist.
Proven where the stakes are highest.
Vulnerabilities found, reported and fixed across French public-sector services, CAC 40 groups, luxury-industry leaders and more. A practice kept sharp as an active researcher on public bug bounty platforms.
French public-sector services (.gouv.fr)
CAC 40 groups
Luxury-industry leaders
YesWeHack & Intigriti researcher
A few real findings, anonymized and fixed
I never disclose a client's name or the vulnerabilities found.
Questions, answered.
Do you sign NDAs?
Yes. Confidentiality is the default, not an upsell. An NDA is signed before any scope is shared, and reporting can be fully encrypted on request.
Will you ever name my organization?
Never. Your identity, your scope and every finding stay strictly between us. Discretion is part of the service.
Do you test mobile applications?
My focus is the web and APIs. That is where I go deepest and find the highest-impact vulnerabilities. For native mobile, I will gladly refer you to a specialist I trust.
How does an engagement start?
A short scoping conversation, a signed agreement, then a defined testing window ending in a clear, prioritized report.
Fixed-scope audit or continuous testing?
Both. A time-boxed audit with a full report, or ongoing results-based testing across your perimeter, whether production, staging or development. Either way, everything runs under a signed testing agreement.
How long does an engagement take?
It depends on the scope. A focused audit can wrap in a few days; a complex application will take one to two weeks. We align on that during scoping.
How much does an audit cost?
Scoped to what you actually need: pricing depends on the size and complexity of your perimeter. We define it together in a first, no-commitment conversation.
Start with a conversation.
Tell me what you'd like tested. Everything you send is treated as strictly confidential.
The right time to reach out
- You're about to put a new site or feature live.
- You handle sensitive data and have never had your application audited.
- You expose an API and aren't sure the authorizations hold.
- A client, an insurer or a compliance rule requires a penetration test.
- A scanner flagged something and you want human validation.
Message received.
Thank you for your message. I will get back to you within 24 business hours.