Web & API security services.
I am an independent security researcher based in France. My job is to attack your applications before someone else does it for the wrong reasons, then hand you everything you need to fix what I found. These are the engagements I run most often.
Six ways to get your systems tested.
Every one of them rests on manual research. An automated scanner only finds what has already been catalogued. The flaws that cost real money require understanding your business logic, and that part does not automate. They get triggered when you need them: before a launch, after a rebuild, or to qualify an alert nobody can settle.
Web penetration testing
Your application is live. I test it the way a real attacker would: hunting for the path nobody planned for, without breaking anything and without your users noticing.
Read more02API security audit
REST, JSON, GraphQL. An API has no interface to lie to you with: it answers exactly what it is asked. What remains is checking it only answers the right people.
Read more03WordPress penetration testing
Plugins, themes, roles, admin surface. The WordPress core is solid, but what gets stacked on top of it is far less so, and that is almost always where hackers get in.
Read more04Website security audit
Brochure site, online store or CMS. Most of what hits a public website is aimed at nobody in particular: it sweeps, it finds, it comes back.
Read more05Authentication and access control
Who can actually do what. IDOR, privilege escalation, tenant isolation: the most common flaw there is, and the one no tool can see.
Read moreContinuous testing
An audit is a snapshot. If your product ships every two weeks, that snapshot goes stale fast. Continuous testing follows the perimeter over time.
Which one is yours?
It is not your industry that decides which engagement fits, it is where your project stands. Three questions settle it.
Is the application already live?
If it is, you want web penetration testing: we work on the real system, with real data and real behaviour, which no staging environment reproduces faithfully. If it is not, we scope a pre-launch audit against a representative staging copy.
Where does your sensitive data live?
If most of the business logic sits behind endpoints consumed by a JavaScript front end or a mobile app, you want an API security audit. That is where I find the most serious flaws today, because access controls there are often assumed rather than verified.
What is the site running on?
If the answer is WordPress, the ways in are specific enough to deserve their own approach, which is what WordPress penetration testing covers.
You do not have to work this out alone. Describe your situation and I will tell you what makes sense, including when the answer is "you do not need me yet".
What never changes.
- A signed testing agreement and NDA before any access at all.
- A defined testing window, known only to you if that is what you want.
- A report prioritized by real severity, not by theoretical score.
- A reproducible proof of concept for every finding.
- A retest of every fix, included, at no extra charge.
- A debrief with your technical team, in plain language.
Start with a conversation.
Tell me what you would like tested. The first conversation carries no commitment, and everything you send is treated as strictly confidential. Based in France, working remotely across Europe and worldwide, in English or French.